HTML Injection Vulnerability in SilverStripe Asset Gallery
CVE-2024-47605

5.4MEDIUM

Key Information:

Vendor
CVE Published:
14 January 2025

What is CVE-2024-47605?

The silverstripe-asset-admin, a component of SilverStripe, contains an HTML injection vulnerability that arises during the 'insert media' functionality. This vulnerability occurs when the oEmbed JSON provided includes an HTML attribute, which subsequently replaces an embed shortcode without proper sanitization. Consequently, this flaw allows for the execution of arbitrary script payloads on both the CMS interface and the front-end of websites utilizing the application. Users are strongly advised to upgrade to silverstripe/framework version 5.3.8 or later as there are no known workarounds to mitigate this issue.

Affected Version(s)

silverstripe-asset-admin < 5.3.8

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.