PT-2024-40096 · Microsoft · Internet Explorer

Published

2024-05-23

·

Updated

2024-05-23

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Silverstripe versions prior to a fixed version (affected versions not specified)
Description: The issue affects Internet Explorer browsers, where requests do not encode all entities in the URL string. As a result, when rewriting hashlinks, SSViewer::process() directly outputs $ SERVER['REQUEST URI'], inserting unencoded entities into output content. This allows JavaScript code to be inserted into the page as-is, potentially leading to security issues. For example, a request like "GET /site/cars/brands/toyota?one=1"onmouseover="alert('things');"" can insert JavaScript code into the page.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

GHSA-5F5V-5C3V-GW5V

Affected Products

Internet Explorer