Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Silverstripe silverstripe/framework through 4.10.0 allows XSS, inside of script tags that can can be added to website content via XHR by an authenticated CMS user if the cwp-core module is not installed on the sanitise_server_side contig is not set to true in project code.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
silverstripe framework 跨站脚本漏洞
Vulnerability Description
silverstripe framework是一套CMS网站框架。 silverstripe framework 4.10.0版本及之前版本存在安全漏洞,该漏洞源于脚本内的标记可以由经过身份验证的CMS用户通过XHR添加到网站内容中。
CVSS Information
N/A
Vulnerability Type
N/A