CVE-2024-32981
17.07.2024, 20:15
Silverstripe framework is the PHP framework forming the base for the Silverstripe CMS. In affected versions a bad actor with access to edit content in the CMS could add send a specifically crafted encoded payload to the server, which could be used to inject a JavaScript payload on the front end of the site. The payload would be sanitised on the client-side, but server-side sanitisation doesn't catch it. The server-side sanitisation logic has been updated to sanitise against this type of attack in version 5.2.16. All users are advised to upgrade. There are no known workarounds for this vulnerability.
| Vendor | Product | Version |
|---|---|---|
| silverstripe | framework | 𝑥 < 5.2.16 |
𝑥
= Vulnerable software versions
References