JavaScript Injection Vulnerability in Silverstripe CMS by Silverstripe
CVE-2025-30148
5.4MEDIUM
What is CVE-2025-30148?
The Silverstripe CMS, built on the Silverstripe Framework, was found to be susceptible to a JavaScript injection vulnerability due to inadequate server-side sanitization. Attackers with edit access could exploit this flaw by sending a malicious encoded payload to the server. While client-side measures may have provided some defense against this type of attack, they proved insufficient. The server-side sanitization logic has since been updated to effectively neutralize this risk. Users are encouraged to upgrade to version 5.3.23 or later to mitigate the vulnerability.
Affected Version(s)
silverstripe-framework < 5.3.23
