In SilverStripe through 4.5, malicious users with a valid Silverstripe CMS login (usually CMS access) can craft profile information which can lead to XSS for other users through specially crafted login form URLs.
{ "cpes": [ "cpe:2.3:a:silverstripe:silverstripe:*:*:*:*:*:*:*:*" ], "severity": "Medium" }