ZeroHour

CVE-2020-9311

CVSS 3.1
5.4 medium
EPSS
<1%p45
Published
()
Modified
Description

In SilverStripe through 4.5, malicious users with a valid Silverstripe CMS login (usually CMS access) can craft profile information which can lead to XSS for other users through specially crafted login form URLs.

Vendors
silverstripe
Products
silverstripe
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.