CVE-2017-5197Cross-site Scripting in CMS

Severity
6.1MEDIUMNVD
EPSS
0.3%
top 50.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 6
Latest updateMay 14

Description

There is XSS in SilverStripe CMS before 3.4.4 and 3.5.x before 3.5.2. The attack vector is a page name. An example payload is a crafted JavaScript event handler within a malformed SVG element.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

Packagistsilverstripe/cms3.5.03.5.2+1

🔴Vulnerability Details

2
GHSA
Silverstripe CMS XSS Vulnerability2022-05-14
OSV
Silverstripe CMS XSS Vulnerability2022-05-14