PT-2024-25029 · Silverstripe · Silverstripe/Framework

Jack Wallace

·

Published

2024-07-17

·

Updated

2025-09-04

·

CVE-2024-32981

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Silverstripe framework versions prior to 5.2.16
Description A bad actor with access to edit content in the CMS could send a specifically crafted encoded payload to the server, which could be used to inject a JavaScript payload on the front end of the site. The payload would be sanitised on the client-side, but server-side sanitisation doesn't catch it.
Recommendations For versions prior to 5.2.16, upgrade to version 5.2.16 or later to resolve the issue. At the moment, there is no information about other workarounds for this vulnerability.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-32981
GHSA-CHX7-9X8H-R5MG

Affected Products

Silverstripe/Framework