Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Ed Chipman

Researcher fromWebbuilders Group
#43040of 53,624
6.1Total CVSS
Vulnerabilities · 1
PT-2020-10136
6.1
2020-02-17
Silverstripe · Silverstripe · CVE-2019-19325
**Name of the Vulnerable Software and Affected Versions** SilverStripe versions 4.4.x through 4.4.4 SilverStripe versions 4.5.x through 4.5.1 **Description** The issue allows Reflected XSS on the login form and custom forms. Silverstripe Forms permit malicious HTML or JavaScript to be inserted through non-scalar `FormField` attributes, enabling XSS (Cross-Site Scripting) on some forms built with user input (Request data). This can lead to phishing attempts to obtain a user's credentials or other sensitive user input. **Recommendations** For SilverStripe versions 4.4.x through 4.4.4, update to version 4.4.5 or later. For SilverStripe versions 4.5.x through 4.5.1, update to version 4.5.2 or later.