CVE-2020-25102

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
03/09/2020
Last modified:
10/09/2020

Description

silverstripe-advancedreports (aka the Advanced Reports module for SilverStripe) 1.0 through 2.0 is vulnerable to Cross-Site Scripting (XSS) because it is possible to inject and store malicious JavaScript code. The affects admin/advanced-reports/DataObjectReport/EditForm/field/DataObjectReport/item (aka report preview) when an SVG document is provided in the Description parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:advanced_reports_project:advanced_reports:*:*:*:*:*:silverstripe:*:* 1.0 (including) 2.0 (including)