Lucene search

K
osvGoogleOSV:GHSA-XGPF-P52J-PF7M
HistoryMar 24, 2021 - 5:42 p.m.

XSS in CreateQueuedJobTask

2021-03-2417:42:02
Google
osv.dev
10
silverstripe cms
symbiote
queuedjobs
cross site scripting
arbitrary payload
dev task
url injection

EPSS

0.001

Percentile

29.3%

A vulnerability has been identified in the Silverstripe CMS 3 and 4 version of the symbiote/silverstripe-queuedjobs module. A Cross Site Scripting vulnerability allows an attacker to inject an arbitrary payload in the CreateQueuedJobTask dev task via a specially crafted URL.

EPSS

0.001

Percentile

29.3%