Vulnerability DatabaseGHSA-frm9-7pm9-5rgc

GHSA-frm9-7pm9-5rgc
PHP vulnerability analysis and mitigation

Overview

The SilverStripe comments module (silverstripe/comments) was found to contain a security vulnerability related to an outdated version of jQuery that includes Cross-site Scripting (XSS) vulnerabilities. The issue was identified and tracked as SS-2018-015, affecting versions 1.3.0 through 3.1.0. The vulnerability was disclosed on May 28, 2018, impacting multiple SilverStripe components including the comments module, cwp/starter-theme, and cwp/watea-theme (SilverStripe Advisory, GitHub Advisory).

Technical details

The vulnerability has been assigned a CVSS v3.1 base score of 4.4 (Moderate severity) with the following metrics: Network attack vector, High attack complexity, Low privileges required, User interaction required, Changed scope, Low confidentiality impact, Low integrity impact, and No availability impact. The technical vector string is CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N. The vulnerability is classified as CWE-79, which relates to Cross-site Scripting (GitHub Advisory).

Impact

The vulnerability could potentially allow XSS attacks if user input is used in certain contexts with the outdated jQuery version. While no known exploits were found in existing usage, custom implementations of the affected themes could have made them exploitable (SilverStripe Advisory).

Exploitability

The vulnerability requires high attack complexity and user interaction for successful exploitation. While no known exploits have been found in existing usage, customizations to the affected themes could potentially make them exploitable (GitHub Advisory).

Mitigation and workarounds

The vulnerability was patched in version 3.1.1 of the silverstripe/comments module. CWP 2.0.0 was released with the fixed cwp/starter-theme and silverstripe/comments module, and SilverStripe 4.2.0 included the fixed silverstripe-themes/simple theme (SilverStripe Advisory).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-71537MEDIUM6.5
  • PHP logoPHP
  • paymenter/paymenter
NoYesSep 18, 2026
CVE-2026-77616MEDIUM6.1
  • PHP logoPHP
  • mediawiki/semantic-media-wiki
NoYesSep 18, 2026
CVE-2026-77610MEDIUM6.1
  • PHP logoPHP
  • mediawiki/semantic-media-wiki
NoYesSep 18, 2026
CVE-2026-77609MEDIUM6.1
  • PHP logoPHP
  • mediawiki/semantic-media-wiki
NoYesSep 18, 2026
CVE-2026-77608MEDIUM6.1
  • PHP logoPHP
  • mediawiki/semantic-media-wiki
NoYesSep 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management