PT-2022-24544 · Silverstripe · Silverstripe/Framework+2
Steve Boyd
·
Published
2022-11-21
·
Updated
2025-04-29
·
CVE-2022-38724
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Silverstripe silverstripe/framework versions 4.11.0 and earlier
Silverstripe silverstripe/assets versions 1.11.0 and earlier
Silverstripe silverstripe/asset-admin versions 1.11.0 and earlier
Description
The issue allows for cross-site scripting (XSS) attacks. A malicious content author could add arbitrary attributes to HTML editor shortcodes, potentially injecting a JavaScript payload on the site's front end. The shortcode providers that ship with Silverstripe CMS have been reviewed, and attribute whitelists have been implemented where necessary to mitigate this risk.
Recommendations
For silverstripe/framework versions 4.11.0 and earlier, update to a version that includes the attribute whitelists for shortcode providers.
For silverstripe/assets versions 1.11.0 and earlier, update to a version that includes the attribute whitelists for shortcode providers.
For silverstripe/asset-admin versions 1.11.0 and earlier, update to a version that includes the attribute whitelists for shortcode providers.
As a temporary workaround, consider restricting the ability to add arbitrary attributes to HTML editor shortcodes until a patch is available.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Silverstripe Asset-Admin
Silverstripe/Assets
Silverstripe/Framework