GHSA-hhvj-mcrx-3vcf: silverstripe/framework has Cross-site Scripting vulnerability in page name
silverstripe/framework is vulnerable to XSS in Page name where the payload "><svg/onload=alert(/xss/)>
will trigger an XSS alert.
References
- github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/framework/SS-2017-001-1.yaml
- github.com/advisories/GHSA-hhvj-mcrx-3vcf
- github.com/silverstripe/silverstripe-framework
- github.com/silverstripe/silverstripe-framework/commit/9574d627f95aca7ae0fcefcae2bf56215777e190
- www.silverstripe.org/download/security-releases/ss-2017-001
Detect and mitigate GHSA-hhvj-mcrx-3vcf with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →