silverstripeCMS Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2015-8606 - Vulnerability Database

silverstripeCMS Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2015-8606

Medium
Reference: CVE-2015-8606
Title: silverstripeCMS Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

Multiple cross-site scripting (XSS) vulnerabilities in SilverStripe CMS amp Framework before 3.1.16 and 3.2.x before 3.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) Locale or (2) FailedLoginCount parameter to admin/security/EditForm/field/Members/item/new/ItemEditForm.