PT-2012-5695 · Silverstripe · Silverstripe

Henri Salo

·

Published

2012-09-17

·

Updated

2022-05-17

·

CVE-2012-4968

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions SilverStripe versions 2.3.x through 2.3.12 SilverStripe versions 2.4.x through 2.4.6
Description The issue allows remote attackers to inject arbitrary web script or HTML via crafted strings to various methods in a template. The affected methods include AbsoluteLinks, BigSummary, ContextSummary, EscapeXML, FirstParagraph, FirstSentence, Initial, LimitCharacters, LimitSentences, LimitWordCount, LimitWordCountXML, Lower, LowerCase, NoHTML, Summary, Upper, UpperCase, or URL.
Recommendations For SilverStripe versions 2.3.x through 2.3.12, update to version 2.3.13 or later. For SilverStripe versions 2.4.x through 2.4.6, update to version 2.4.7 or later. As a temporary workaround, consider restricting the use of the vulnerable methods in templates until a patch is available.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-4968
GHSA-V358-RVXR-WFFX

Affected Products

Silverstripe