CVE-2022-25238 Information
Jun 29, 2022
cve
Description
Silverstripe silverstripe/framework through 4.10.0 allows XSS inside of script tags that can can be added to website content via XHR by an authenticated CMS user if the cwp-core module is not installed on the sanitise_server_side contig is not set to true in project code.
Reference
https://docs.silverstripe.org/en/4/changelogs/4.10.1/ https://www.silverstripe.org/download/security-releases/ https://www.silverstripe.org/blog/tag/release https://forum.silverstripe.org/c/releases
Share on: