PT-2024-25029 · Silverstripe · Silverstripe/Framework
Jack Wallace
·
Published
2024-07-17
·
Updated
2025-09-04
·
CVE-2024-32981
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Silverstripe framework versions prior to 5.2.16
Description
A bad actor with access to edit content in the CMS could send a specifically crafted encoded payload to the server, which could be used to inject a JavaScript payload on the front end of the site. The payload would be sanitised on the client-side, but server-side sanitisation doesn't catch it.
Recommendations
For versions prior to 5.2.16, upgrade to version 5.2.16 or later to resolve the issue.
At the moment, there is no information about other workarounds for this vulnerability.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Silverstripe/Framework