Skip to content

Commit aa46c9b

Browse files
1 parent e610f80 commit aa46c9b

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

advisories/github-reviewed/2025/01/GHSA-7cmp-cgg8-4c82/GHSA-7cmp-cgg8-4c82.json

+2-2
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,13 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-7cmp-cgg8-4c82",
4-
"modified": "2025-01-14T22:18:53Z",
4+
"modified": "2025-01-14T23:04:40Z",
55
"published": "2025-01-14T22:18:52Z",
66
"aliases": [
77
"CVE-2024-47605"
88
],
99
"summary": "Silverstripe Framework has a XSS via insert media remote file oembed",
10-
"details": "### Impact\n\nWhen using the \"insert media\" functionality, the linked oEmbed JSON includes an HTML attribute which will replace the embed shortcode. The HTML is not sanitized before replacing the shortcode, allowing a script payload to be executed on both the CMS and the front-end of the website.\n\n## References\n\n- https://www.silverstripe.org/download/security-releases/cve-2024-47605\n\n\n",
10+
"details": "### Impact\n\nWhen using the \"insert media\" functionality, the linked oEmbed JSON includes an HTML attribute which will replace the embed shortcode. The HTML is not sanitized before replacing the shortcode, allowing a script payload to be executed on both the CMS and the front-end of the website.\n\n## References\n\n- https://www.silverstripe.org/download/security-releases/cve-2024-47605\n\n## Reported by\n\nJames Nicoll from [Fujitsu Cyber Security Services](https://www.fujitsu.com/nz/services/security/)",
1111
"severity": [
1212
{
1313
"type": "CVSS_V3",

0 commit comments

Comments
 (0)