CVE-2026-55779
PHP 취약성 분석 및 완화

개요

CVE-2026-55779 is a stored Cross-Site Scripting (XSS) vulnerability in the silverstripe/versioned Composer package (Silverstripe Versioned) affecting all versions prior to 3.2.1. The flaw exists in RestoreAction::getRestoreMessage() within src/RestoreAction.php, where user-controlled fields (Title, URLSegment, CMSEditLink(), and changedProperty['value']) are inserted into an HTML-rendered restoration notification without applying Convert::raw2xml() encoding. It was discovered and disclosed on June 24, 2026, with the fix released the same day. The vulnerability carries a CVSS v3.1 base score of 5.4 (Medium) (GitHub Advisory, Feedly).

기술적 세부 사항

The root cause is improper output encoding (CWE-79) in the getRestoreMessage() method of RestoreAction.php. The method builds an ArchiveAdmin restore notification rendered as CAST_HTML but interpolates $restoredItem->Title, $restoredItem->URLSegment, $restoredItem->CMSEditLink(), and $changedProperty['value'] directly into the HTML string without escaping. An attacker who can create or modify a page with a crafted title or URL segment (e.g., <iframe src=javascript:alert(1)> or <button formaction="javascript:alert(1)">) can store a malicious payload that executes when an administrator restores the archived page in the CMS. The fix applies Convert::raw2xml() to all user-supplied values before interpolation (GitHub Commit, GitHub Advisory).

영향

Successful exploitation allows stored JavaScript to execute in the browser of a CMS administrator who restores an archived page, compromising the confidentiality and integrity of the administrator's CMS session. An attacker could steal session cookies, perform unauthorized CMS actions (such as modifying content or creating admin accounts), or conduct further attacks against the CMS backend. Availability is not directly impacted, and the scope is limited to the CMS session of the triggering administrator (GitHub Advisory, Feedly).

악용 가능성

No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the disclosure date. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires that an attacker be able to create or manipulate a page with a crafted title or URL segment prior to archival, and that a CMS administrator subsequently restores that page — making it a stored XSS with a required user interaction step (Feedly).

착취 단계

  1. Craft a malicious page: As a user with page-creation or editing privileges (or via another injection vector), create or modify a Silverstripe CMS page and set its Title or URLSegment field to a JavaScript payload, e.g., <iframe src=javascript:alert(document.cookie)> or <button formaction="javascript:alert(1)">Click</button>.
  2. Archive the page: Ensure the malicious page is archived (moved to the archive) so it appears in the ArchiveAdmin interface.
  3. Wait for administrator action: Wait for a CMS administrator to navigate to the ArchiveAdmin section and initiate a restore of the archived page containing the crafted title or URL segment.
  4. Trigger XSS execution: When the administrator restores the page, RestoreAction::getRestoreMessage() builds the notification message using the unescaped Title or URLSegment, and the message is rendered as HTML (CAST_HTML) in the administrator's browser, executing the injected JavaScript.
  5. Achieve objective: The executed script can exfiltrate the administrator's session cookie, perform authenticated CMS actions on their behalf, or deliver further payloads (GitHub Commit, GitHub Advisory).

타협의 징후

  • Logs: CMS audit logs showing a page restore action performed by an administrator on a page with an unusual or HTML-encoded title or URL segment containing script tags, iframe elements, or event handler attributes.
  • Network: Outbound requests from the administrator's browser to unexpected external domains immediately following a page restore action in the CMS (potential session cookie exfiltration).
  • File System / CMS Content: Pages in the archive with Title or URLSegment fields containing HTML tags such as <script>, <iframe>, <button formaction=...>, or JavaScript URI schemes (javascript:).
  • Process/Session: Unexpected CMS administrative actions (new admin user creation, content modification, settings changes) occurring shortly after a page restore event, potentially indicating session hijacking.

완화 및 해결 방법

Upgrade silverstripe/versioned to version 3.2.1 or later, which applies Convert::raw2xml() to all user-supplied fields (Title, URLSegment, CMSEditLink(), and changedProperty['value']) before rendering the restore notification message (GitHub Release, GitHub Advisory). As interim mitigations, enforce a Content Security Policy (CSP) that disallows inline script execution in the CMS, and restrict page creation/editing privileges to trusted users only. Note that the fix has not been backported to the Silverstripe 5 (silverstripe-versioned v2) branch as of the disclosure date; Silverstripe 5 users should consult the official security release blog for guidance (Silverstripe Blog).

커뮤니티 반응

The vulnerability was reported by Steve Boyd of Silverstripe Ltd. and fixed by developer emteknetnz (GitHub Advisory). Community discussion on the fix pull request raised concerns that the patch was not backported to Silverstripe 5 (silverstripe-versioned v2), leaving non-EOL Silverstripe 5.4 installations without a direct fix. A community member (xini) criticized the project's security backport policy, arguing it leaves supported versions knowingly vulnerable and that the contribution process needs to be more open to address such issues promptly (GitHub PR #541). Silverstripe acknowledged the concern and published a security release blog post addressing the situation.

추가 자료


근원이 보고서는 AI를 사용하여 생성되었습니다.

관련 PHP 취약점:

CVE ID

심각도

점수

기술

구성 요소 이름

CISA KEV 익스플로잇

수정 사항이 있습니다.

게시된 날짜

CVE-2026-54721HIGH8.8
  • PHP logoPHP
  • composer://silverstripe/userforms
아니요Aug 27, 2026
CVE-2026-55584HIGH7.5
  • PHP logoPHP
  • phpsysinfo
아니요Aug 28, 2026
CVE-2026-55779MEDIUM5.4
  • PHP logoPHP
  • composer://silverstripe/versioned
아니요Aug 28, 2026
CVE-2026-55696MEDIUM4.3
  • PHP logoPHP
  • privatebin/privatebin
아니요Aug 28, 2026
CVE-2026-55891NONE해당 사항 없음
  • PHP logoPHP
  • privatebin
아니요Aug 28, 2026

무료 취약성 평가

클라우드 보안 태세를 벤치마킹합니다

9개의 보안 도메인에서 클라우드 보안 관행을 평가하여 위험 수준을 벤치마킹하고 방어의 허점을 식별합니다.

평가 요청

추가 Wiz 리소스

맞춤형 데모 받기

맞춤형 데모 신청하기

"내가 본 최고의 사용자 경험은 클라우드 워크로드에 대한 완전한 가시성을 제공합니다."
데이비드 에슬릭최고정보책임자(CISO)
"Wiz는 클라우드 환경에서 무슨 일이 일어나고 있는지 볼 수 있는 단일 창을 제공합니다."
아담 플레처최고 보안 책임자(CSO)
"우리는 Wiz가 무언가를 중요한 것으로 식별하면 실제로 중요하다는 것을 알고 있습니다."
그렉 포니아토프스키위협 및 취약성 관리 책임자