CVE-2020-9311

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
15/07/2020
Last modified:
22/07/2020

Description

In SilverStripe through 4.5, malicious users with a valid Silverstripe CMS login (usually CMS access) can craft profile information which can lead to XSS for other users through specially crafted login form URLs.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:silverstripe:silverstripe:*:*:*:*:*:*:*:* 3.0.0 (including) 3.7.5 (excluding)