There is XSS in SilverStripe CMS before 3.4.4 and 3.5.x before 3.5.2. The attack vector is a page name. An example payload is a crafted JavaScript event handler within a malformed SVG element.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/96572 | Third Party Advisory VDB Entry |
https://www.silverstripe.org/download/security-releases/ | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2017-03-06T06:11:00
Updated: 2017-03-07T10:57:01
Reserved: 2017-01-06T00:00:00
Link: CVE-2017-5197
JSON object: View
NVD Information
Status : Analyzed
Published: 2017-03-06T06:59:00.223
Modified: 2019-03-19T12:12:37.510
Link: CVE-2017-5197
JSON object: View
Redhat Information
No data.
CWE