Security Advisory

CVE-2017-14498

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-09-15 18:00:00
Last updated 2024-08-05 19:27:40
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

SilverStripe CMS before 3.6.1 has XSS via an SVG document that is mishandled by (1) the Insert Media option in the content editor or (2) an admin/assets/add pathname, as demonstrated by the admin/pages/edit/EditorToolbar/MediaForm/field/AssetUploadField/upload URI, aka issue SS-2017-017.