source: https://www.securityfocus.com/bid/62782/info SilverStripe is prone to multiple HTML-injection vulnerabilities because it fails to sufficiently sanitize user-supplied input. Attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials and control how the site is rendered to the user; other attacks are also possible. SilverStripe 3.0.5 is vulnerable; other versions may also be affected. Proof of Concept: ================= 1.1 The first persistent input validation web vulnerability can be exploited by remote attackers with low privileged application user accounts and low required user interaction. For demonstration or reproduce ... PoC: Groups & Rollen (Roles) - Print
Vorname | Nachname |
---|
Gedruckt am 11:44pm, 22/09/2013
Gedruckt von a%20>"