GHSA-v358-rvxr-wffx

Suggest an improvement
Source
https://github.com/advisories/GHSA-v358-rvxr-wffx
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-v358-rvxr-wffx/GHSA-v358-rvxr-wffx.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-v358-rvxr-wffx
Aliases
  • CVE-2012-4968
Published
2022-05-17T05:22:19Z
Modified
2024-01-12T20:41:37Z
Summary
Silverstripe XSS Vulnerabilities
Details

Multiple cross-site scripting (XSS) vulnerabilities in SilverStripe 2.3.x before 2.3.13 and 2.4.x before 2.4.7 allow remote attackers to inject arbitrary web script or HTML via

  1. a crafted string to the AbsoluteLinks
  2. BigSummary
  3. ContextSummary
  4. EscapeXML
  5. FirstParagraph
  6. FirstSentence
  7. Initial
  8. LimitCharacters
  9. LimitSentences
  10. LimitWordCount
  11. LimitWordCountXML
  12. Lower
  13. LowerCase
  14. NoHTML
  15. Summary
  16. Upper
  17. UpperCase, or
  18. URL method in a template,

different vectors than CVE-2012-0976.

Database specific
{
    "cwe_ids": [
        "CWE-79"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2024-01-12T20:16:37Z",
    "nvd_published_at": "2012-09-17T17:55:00Z",
    "severity": "MODERATE"
}
References

Affected packages

Packagist / silverstripe/framework

Package

Name
silverstripe/framework
Purl
pkg:composer/silverstripe/framework

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.3
Fixed
2.3.13

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-v358-rvxr-wffx/GHSA-v358-rvxr-wffx.json"

Packagist / silverstripe/framework

Package

Name
silverstripe/framework
Purl
pkg:composer/silverstripe/framework

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.4
Fixed
2.4.7

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-v358-rvxr-wffx/GHSA-v358-rvxr-wffx.json"