Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Advanced Reports Project Subscribe
Filtered by product Advanced Reports
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-25102 1 Advanced Reports Project 1 Advanced Reports 2020-09-10 4.3 MEDIUM 6.1 MEDIUM
silverstripe-advancedreports (aka the Advanced Reports module for SilverStripe) 1.0 through 2.0 is vulnerable to Cross-Site Scripting (XSS) because it is possible to inject and store malicious JavaScript code. The affects admin/advanced-reports/DataObjectReport/EditForm/field/DataObjectReport/item (aka report preview) when an SVG document is provided in the Description parameter.