PT-2022-24544 · Silverstripe · Silverstripe/Framework+2

Steve Boyd

·

Published

2022-11-21

·

Updated

2025-04-29

·

CVE-2022-38724

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Silverstripe silverstripe/framework versions 4.11.0 and earlier Silverstripe silverstripe/assets versions 1.11.0 and earlier Silverstripe silverstripe/asset-admin versions 1.11.0 and earlier
Description The issue allows for cross-site scripting (XSS) attacks. A malicious content author could add arbitrary attributes to HTML editor shortcodes, potentially injecting a JavaScript payload on the site's front end. The shortcode providers that ship with Silverstripe CMS have been reviewed, and attribute whitelists have been implemented where necessary to mitigate this risk.
Recommendations For silverstripe/framework versions 4.11.0 and earlier, update to a version that includes the attribute whitelists for shortcode providers. For silverstripe/assets versions 1.11.0 and earlier, update to a version that includes the attribute whitelists for shortcode providers. For silverstripe/asset-admin versions 1.11.0 and earlier, update to a version that includes the attribute whitelists for shortcode providers. As a temporary workaround, consider restricting the ability to add arbitrary attributes to HTML editor shortcodes until a patch is available.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-38724
GHSA-9CX2-HJ6M-FV58

Affected Products

Silverstripe Asset-Admin
Silverstripe/Assets
Silverstripe/Framework