CVE-2025-25197

Source
https://cve.org/CVERecord?id=CVE-2025-25197
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-25197.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-25197
Aliases
Published
2025-04-10T12:58:13.674Z
Modified
2026-04-10T05:24:19.071868Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
Silverstripe Elemental enables XSS attacks in elemental "Content blocks in use" reports
Details

Silverstripe Elemental extends a page type to swap the content area for a list of manageable elements to compose a page out of rather than a single text field. An elemental block can include an XSS payload, which can be executed when viewing the "Content blocks in use" report. The vulnerability is specific to that report and is a result of failure to cast input prior to including it in the grid field. This vulnerability is fixed in 5.3.12.

Database specific
{
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/25xxx/CVE-2025-25197.json",
    "cwe_ids": [
        "CWE-79"
    ]
}
References

Affected packages

Git / github.com/silverstripe/silverstripe-elemental

Affected ranges

Type
GIT
Repo
https://github.com/silverstripe/silverstripe-elemental
Events

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-25197.json"