Description
There is XSS in SilverStripe CMS before 3.4.4 and 3.5.x before 3.5.2. The attack vector is a page name. An example payload is a crafted JavaScript event handler within a malformed SVG element.
Remediation
References
Related Vulnerabilities
PHP-Fusion URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2020-23182)
PHP Integer Overflow or Wraparound Vulnerability (CVE-2016-5770)
WordPress Plugin Cartogiraffe Map Cross-Site Scripting (1.0)
WordPress Plugin WordPress Ad Widget Local File Inclusion (2.11.0)
Apache Tomcat URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2023-41080)