CVE-2020-9311
EUVD-2022-203015.07.2020, 21:15
In SilverStripe through 4.5, malicious users with a valid Silverstripe CMS login (usually CMS access) can craft profile information which can lead to XSS for other users through specially crafted login form URLs.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| silverstripe | silverstripe | 3.0.0 ≤ 𝑥 < 3.7.5 |
𝑥
= Vulnerable software versions