silverstripeCMS Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2022-28803 - Vulnerability Database
silverstripeCMS Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2022-28803
Medium
Reference:
CVE-2022-28803
Title:
silverstripeCMS Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:
In SilverStripe Framework through 2022-04-07 Stored XSS can occur in javascript link tags added via XMLHttpRequest (XHR).