HTML Injection Vulnerability in SilverStripe Asset Gallery
CVE-2024-47605
5.4MEDIUM
What is CVE-2024-47605?
The silverstripe-asset-admin, a component of SilverStripe, contains an HTML injection vulnerability that arises during the 'insert media' functionality. This vulnerability occurs when the oEmbed JSON provided includes an HTML attribute, which subsequently replaces an embed shortcode without proper sanitization. Consequently, this flaw allows for the execution of arbitrary script payloads on both the CMS interface and the front-end of websites utilizing the application. Users are strongly advised to upgrade to silverstripe/framework version 5.3.8 or later as there are no known workarounds to mitigate this issue.
Affected Version(s)
silverstripe-asset-admin < 5.3.8
