PT-2022-23993 · Silverstripe · Silverstripe/Framework

Tf1T

·

Published

2022-11-21

·

Updated

2025-04-25

·

CVE-2022-37429

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Silverstripe silverstripe/framework versions through 4.11
Description The issue allows for XSS via a JavaScript payload to the href attribute of a link by splitting a javascript URL with white space characters. A malicious content author could exploit this by adding a JavaScript payload to the href attribute of a link. An attacker must have access to the CMS to exploit this issue.
Recommendations For versions through 4.11, as a temporary workaround, consider restricting access to the href attribute of links to minimize the risk of exploitation. Avoid using the href attribute in links with JavaScript URLs until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-37429
GHSA-WC6R-4GGC-79W5

Affected Products

Silverstripe/Framework