Description
In SilverStripe through 4.5, malicious users with a valid Silverstripe CMS login (usually CMS access) can craft profile information which can lead to XSS for other users through specially crafted login form URLs.
Remediation
References
Related Vulnerabilities
WordPress Plugin CM Pop-Up banners for WordPress SQL Injection (1.5.10)
WordPress Plugin Product Catalog Multiple SQL Injection Vulnerabilities (2.1)
Sqlite Improper Resource Shutdown or Release Vulnerability (CVE-2015-3415)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-2151)