CVE-2020-9311

In SilverStripe through 4.5, malicious users with a valid Silverstripe CMS login (usually CMS access) can craft profile information which can lead to XSS for other users through specially crafted login form URLs.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:silverstripe:silverstripe:*:*:*:*:*:*:*:*

Information

Published : 2020-07-15 14:15

Updated : 2020-07-22 08:15


NVD link : CVE-2020-9311

Mitre link : CVE-2020-9311


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Advertisement

dedicated server usa

Products Affected

silverstripe

  • silverstripe