CVE-2017-14498

MEDIUM

SilverStripe CMS <3.6.1 - XSS

Title source: llm
STIX 2.1

Description

SilverStripe CMS before 3.6.1 has XSS via an SVG document that is mishandled by (1) the Insert Media option in the content editor or (2) an admin/assets/add pathname, as demonstrated by the admin/pages/edit/EditorToolbar/MediaForm/field/AssetUploadField/upload URI, aka issue SS-2017-017.

Scores

CVSS v3 6.1
EPSS 0.0037
EPSS Percentile 59.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
silverstripe/cms 0 - 3.6.1Packagist
silverstripe/silverstripe < 3.6.0
Published Sep 15, 2017
Tracked Since Feb 18, 2026