Description
Cross-site scripting (XSS) vulnerability in the process function in SSViewer.php in SilverStripe before 2.3.13 and 2.4.x before 2.4.6 allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING to template placeholders, as demonstrated by a request to (1) admin/reports/, (2) admin/comments/, (3) admin/, (4) admin/show/, (5) admin/assets/, and (6) admin/security/.
Remediation
References
Related Vulnerabilities
WordPress Plugin File Manager Unspecified Vulnerability (4.1.4)
Magento Improper Input Validation Vulnerability (CVE-2019-7885)
MyBB Other Vulnerability (CVE-2007-2212)
WordPress Plugin WordPress Landing Pages Multiple Vulnerabilities (1.8.4)
XWikiplatform Incorrect Authorization Vulnerability (CVE-2025-32971)