Silverstripe silverstripe/framework up to and including 4.11 allows XSS (issue 1 of 3) via remote attackers adding a Javascript payload to a page's meta description and get it executed in the versioned history compare view.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
silverstripe framework |