CVE-2021-27938
16.03.2021, 16:15
A vulnerability has been identified in the Silverstripe CMS 3 and 4 version of the symbiote/silverstripe-queuedjobs module. A Cross Site Scripting vulnerability allows an attacker to inject an arbitrary payload in the CreateQueuedJobTask dev task via a specially crafted URL.
Vendor | Product | Version |
---|---|---|
symbiote | silverstripe_queued_jobs | 3.0.0 ≤ 𝑥 < 3.0.2 |
symbiote | silverstripe_queued_jobs | 3.1.0 ≤ 𝑥 < 3.1.4 |
symbiote | silverstripe_queued_jobs | 4.0.0 ≤ 𝑥 < 4.0.7 |
symbiote | silverstripe_queued_jobs | 4.1.0 ≤ 𝑥 < 4.1.2 |
symbiote | silverstripe_queued_jobs | 4.2.0 ≤ 𝑥 < 4.2.4 |
symbiote | silverstripe_queued_jobs | 4.3.0 ≤ 𝑥 < 4.3.3 |
symbiote | silverstripe_queued_jobs | 4.4.0 ≤ 𝑥 < 4.4.3 |
symbiote | silverstripe_queued_jobs | 4.5.0 ≤ 𝑥 < 4.5.1 |
symbiote | silverstripe_queued_jobs | 4.6.0 ≤ 𝑥 < 4.6.4 |
𝑥
= Vulnerable software versions