GHSA-wg4m-vvp6-2hc5

Suggest an improvement
Source
https://github.com/advisories/GHSA-wg4m-vvp6-2hc5
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-wg4m-vvp6-2hc5/GHSA-wg4m-vvp6-2hc5.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-wg4m-vvp6-2hc5
Aliases
  • CVE-2010-1593
Published
2022-05-14T02:45:01Z
Modified
2025-04-11T20:58:44.840431Z
Severity
  • 1.3 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U CVSS Calculator
Summary
SilverStripe vulnerable to Cross-site Scripting
Details

Multiple cross-site scripting (XSS) vulnerabilities in SilverStripe before 2.3.5 allow remote attackers to inject arbitrary web script or HTML via (1) the CommenterURL parameter to PostCommentForm, and in the Forum module before 0.2.5 in SilverStripe before 2.3.5 allow remote attackers to inject arbitrary web script or HTML via (2) the Search parameter to forums/search (aka the search script).

Database specific
{
    "github_reviewed": true,
    "nvd_published_at": "2010-04-28T23:30:00Z",
    "severity": "LOW",
    "github_reviewed_at": "2025-04-11T20:01:05Z",
    "cwe_ids": [
        "CWE-79"
    ]
}
References

Affected packages

Packagist / silverstripe/cms

Package

Name
silverstripe/cms
Purl
pkg:composer/silverstripe/cms

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.3.5

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-wg4m-vvp6-2hc5/GHSA-wg4m-vvp6-2hc5.json"

Packagist / silverstripe/framework

Package

Name
silverstripe/framework
Purl
pkg:composer/silverstripe/framework

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.3.5

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-wg4m-vvp6-2hc5/GHSA-wg4m-vvp6-2hc5.json"