Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-07750
HistoryNov 23, 2022 - 12:00 a.m.

Silverstripe framework cross-site scripting vulnerability

2022-11-2300:00:00
China National Vulnerability Database
www.cnvd.org.cn
23
silverstripe
xss
vulnerability
jquery 1.7.2
cve-2019-11358
object.prototype contamination
cross-site scripting
attacks
digital teams
new zealand
platform

0.035 Low

EPSS

Percentile

91.6%

Silverstripe framework is an application from Silverstripe New Zealand. Empowering powerful digital teams by creating a platform for digital change. silverstripe framework 4.10.0 and previous versions contain a cross-site scripting vulnerability that stems from the use of jQuery 1.7.2, which is affected by the CVE-2019-11358 Object.prototype contamination , which can be exploited by attackers to launch cross-site scripting attacks.

CPENameOperatorVersion
silverstripe frameworkle4.11.0