CVE-2020-9311
15.07.2020, 21:15
In SilverStripe through 4.5, malicious users with a valid Silverstripe CMS login (usually CMS access) can craft profile information which can lead to XSS for other users through specially crafted login form URLs.
Vendor | Product | Version |
---|---|---|
silverstripe | silverstripe | 3.0.0 ≤ 𝑥 < 3.7.5 |
𝑥
= Vulnerable software versions