CVE-2011-4958
Silverstripe < 2.3.12 - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in the process function in SSViewer.php in SilverStripe before 2.3.13 and 2.4.x before 2.4.6 allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING to template placeholders, as demonstrated by a request to (1) admin/reports/, (2) admin/comments/, (3) admin/, (4) admin/show/, (5) admin/assets/, and (6) admin/security/.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Stefan Schurtz · textwebappsphp
https://www.exploit-db.com/exploits/36226
References (9)
Scores
EPSS
0.0881
EPSS Percentile
92.4%
Details
CWE
CWE-79
Status
published
Products (25)
silverstripe/silverstripe
< 2.3.12
silverstripe/silverstripe
silverstripe/silverstripe
silverstripe/silverstripe
silverstripe/silverstripe
silverstripe/silverstripe
silverstripe/silverstripe
silverstripe/silverstripe
silverstripe/silverstripe
silverstripe/silverstripe
... and 15 more
Published
Apr 08, 2014
Tracked Since
Feb 18, 2026