CVE-2022-37429
23.11.2022, 02:15
Silverstripe silverstripe/framework through 4.11 allows XSS (issue 1 of 2) via JavaScript payload to the href attribute of a link by splitting a javascript URL with white space characters.
Vendor | Product | Version |
---|---|---|
silverstripe | framework | 3.0.0 ≤ 𝑥 < 4.11.13 |
𝑥
= Vulnerable software versions
References