Description
Multiple cross-site scripting (XSS) vulnerabilities in SilverStripe CMS & Framework before 3.1.16 and 3.2.x before 3.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) Locale or (2) FailedLoginCount parameter to admin/security/EditForm/field/Members/item/new/ItemEditForm.
Remediation
References
Related Vulnerabilities
MySQL CVE-2012-0102 Vulnerability (CVE-2012-0102)
Apache HTTP Server Out-of-bounds Write Vulnerability (CVE-2019-10081)
WordPress Plugin EZ Google Analytics Cross-Site Scripting (4.1.06)
WordPress Plugin Slimstat Analytics PHP Object Injection (4.7)
WordPress Plugin Video Gallery /w YouTube, Vimeo Arbitrary File Upload (8.48)