github.com
https://github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/framework/SS-2024-002.yaml GHSA-74J9-XHQR-6QV3
Reflected Cross Site Scripting (XSS) in error message
Description
If a website has been set to the "dev" environment mode, a URL can be provided which includes an XSS payload which will be executed in the resulting error message.
Description source: GitHub Advisory
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
silverstripe/frameworkBrowse Packagist / silverstripe/framework | GitHub Advisory | Before 5.3.8 · Fixed in 5.3.8 | affected |
References
3github.com
https://github.com/silverstripe/silverstripe-framework silverstripe.org
https://www.silverstripe.org/download/security-releases/ss-2024-002