silverstripeCMS Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2019-14272 - Vulnerability Database

silverstripeCMS Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2019-14272

Medium
Reference: CVE-2019-14272
Title: silverstripeCMS Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

In SilverStripe asset-admin 4.0 there is XSS in file titles managed through the CMS.