{"id":"GHSA-v358-rvxr-wffx","summary":"Silverstripe XSS Vulnerabilities","details":"Multiple cross-site scripting (XSS) vulnerabilities in SilverStripe 2.3.x before 2.3.13 and 2.4.x before 2.4.7 allow remote attackers to inject arbitrary web script or HTML via \n1. a crafted string to the `AbsoluteLinks`\n1. `BigSummary`\n1. `ContextSummary`\n1. `EscapeXML`\n1. `FirstParagraph`\n1. `FirstSentence`\n1. `Initial`\n1. `LimitCharacters`\n1. `LimitSentences`\n1. `LimitWordCount`\n1. `LimitWordCountXML`\n1. `Lower`\n1. `LowerCase`\n1. `NoHTML`\n1. `Summary`\n1. `Upper`\n1. `UpperCase`, or \n1. `URL` method in a template, \n\ndifferent vectors than CVE-2012-0976.","aliases":["CVE-2012-4968"],"modified":"2024-01-12T20:41:37.101821Z","published":"2022-05-17T05:22:19Z","database_specific":{"nvd_published_at":"2012-09-17T17:55:00Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-01-12T20:16:37Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2012-4968"},{"type":"WEB","url":"https://github.com/silverstripe/sapphire/commit/0085876"},{"type":"WEB","url":"https://github.com/silverstripe/silverstripe-framework/commit/0085876495f0f8dda5dc58cb24a8f2220e7baf1e"},{"type":"WEB","url":"https://github.com/silverstripe/silverstripe-framework/commit/15e9e059e5948ccf8f5a36dfcb435ad26ecec334"},{"type":"PACKAGE","url":"https://github.com/silverstripe/silverstripe-framework"},{"type":"WEB","url":"http://doc.silverstripe.org/framework/en/trunk/changelogs/2.3.13"},{"type":"WEB","url":"http://doc.silverstripe.org/framework/en/trunk/changelogs/2.4.7"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2012/04/30/1"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2012/04/30/3"}],"affected":[{"package":{"name":"silverstripe/framework","ecosystem":"Packagist","purl":"pkg:composer/silverstripe/framework"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.3"},{"fixed":"2.3.13"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-v358-rvxr-wffx/GHSA-v358-rvxr-wffx.json"}},{"package":{"name":"silverstripe/framework","ecosystem":"Packagist","purl":"pkg:composer/silverstripe/framework"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.4"},{"fixed":"2.4.7"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-v358-rvxr-wffx/GHSA-v358-rvxr-wffx.json"}}],"schema_version":"1.9.0"}