Register for the AI for Security Summit: Join Figma, Perplexity & Wiz
Vulnerability DatabaseGHSA-779c-7w4p-2c4g

GHSA-779c-7w4p-2c4g
PHP vulnerability analysis and mitigation

Overview

A Cross-Site Scripting (XSS) vulnerability was discovered in the Silverstripe admin WYSIWYG editor, identified as SS-2018-004. The vulnerability affects Silverstripe admin versions 1.0.3-1.0.4 and 1.1.0-1.1.1, and was disclosed on May 28, 2018. The issue was reported by Jeremy Bates at Heyday Digital for Aura Information Security (Silverstripe Advisory).

Technical details

The vulnerability allows malicious actors with CMS access to exploit onmouseover or onmouseout attributes in the WYSIWYG editor to embed malicious JavaScript. The vulnerability has been assigned a CVSS v3.1 base score of 3.8 (Low severity) with the following vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N. The vulnerability is classified as CWE-79, which relates to Cross-Site Scripting (GitHub Advisory).

Impact

The vulnerability can lead to potential data confidentiality and integrity breaches, though both are rated as Low impact. The attack requires high privileges but no user interaction, and while it can be executed over the network, it does not affect system availability (GitHub Advisory).

Exploitability

The vulnerability requires an attacker to have existing access to the CMS, indicating a high privilege requirement. The attack complexity is rated as Low, suggesting that once access is obtained, the vulnerability is relatively straightforward to exploit (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been patched in Silverstripe admin versions 1.0.4 and 1.1.1. Users are advised to upgrade to these patched versions to mitigate the risk (Silverstripe Advisory).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-56829HIGH8.1
  • PHP logoPHP
  • shopper/framework
NoYesSep 15, 2026
CVE-2026-56827HIGH8.1
  • PHP logoPHP
  • shopper/framework
NoYesSep 15, 2026
CVE-2026-84997HIGH7.5
  • PHP logoPHP
  • composer://react/http
NoYesSep 16, 2026
CVE-2026-56831MEDIUM6.5
  • PHP logoPHP
  • shopper/framework
NoYesSep 15, 2026
CVE-2026-56830MEDIUM6.5
  • PHP logoPHP
  • shopper/framework
NoYesSep 15, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management