
Cloud Vulnerability DB
A community-led vulnerabilities database
A Cross-Site Scripting (XSS) vulnerability was discovered in the Silverstripe admin WYSIWYG editor, identified as SS-2018-004. The vulnerability affects Silverstripe admin versions 1.0.3-1.0.4 and 1.1.0-1.1.1, and was disclosed on May 28, 2018. The issue was reported by Jeremy Bates at Heyday Digital for Aura Information Security (Silverstripe Advisory).
The vulnerability allows malicious actors with CMS access to exploit onmouseover or onmouseout attributes in the WYSIWYG editor to embed malicious JavaScript. The vulnerability has been assigned a CVSS v3.1 base score of 3.8 (Low severity) with the following vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N. The vulnerability is classified as CWE-79, which relates to Cross-Site Scripting (GitHub Advisory).
The vulnerability can lead to potential data confidentiality and integrity breaches, though both are rated as Low impact. The attack requires high privileges but no user interaction, and while it can be executed over the network, it does not affect system availability (GitHub Advisory).
The vulnerability requires an attacker to have existing access to the CMS, indicating a high privilege requirement. The attack complexity is rated as Low, suggesting that once access is obtained, the vulnerability is relatively straightforward to exploit (GitHub Advisory).
The vulnerability has been patched in Silverstripe admin versions 1.0.4 and 1.1.1. Users are advised to upgrade to these patched versions to mitigate the risk (Silverstripe Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."