PT-2025-5641 · Silverstripe · Silverstripe

Published

2025-01-14

·

Updated

2025-01-14

CVSS v3.1

0.0

None

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Silverstripe (affected versions not specified)
Description: The issue affects sites in the "dev" environment mode, allowing an XSS payload to be executed in the resulting error message when a specifically crafted URL is provided. This is a misconfiguration issue, as production websites should not be in "dev" mode.
Recommendations: Immediately switch production websites from "dev" mode to "live" mode to prevent exploitation. As a temporary workaround, consider restricting access to the website while it is in "dev" mode to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

GHSA-MQF3-QPC3-G26Q

Affected Products

Silverstripe