silverstripe/silverstripe-installer

silverstripe/silverstripe-installer

Releases388
Frequency2 weeks 3 days
Last Release
Stars169
The installer for Silverstripe CMS and Framework. Check out this repository to start working with Silverstripe!

CVE History

CVEPublishedCVSS v3CVSS v2
4.3 MEDIUM

SilverStripe CMS before 3.6.1 has XSS via an SVG document that is mishandled by (1) the Insert Media option in the content editor or (2) an admin/assets/add pathname, as demonstrated by the admin/pages/edit/EditorToolbar/MediaForm/field/AssetUploadField/upload URI, aka issue SS-2017-017.