silverstripeCMS Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2022-28803 - Vulnerability Database

silverstripeCMS Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2022-28803

Medium
Reference: CVE-2022-28803
Title: silverstripeCMS Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

In SilverStripe Framework through 2022-04-07 Stored XSS can occur in javascript link tags added via XMLHttpRequest (XHR).