Security Advisory

CVE-2020-9311

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2020-07-15 21:00:17
Last updated 2024-08-04 10:26:15
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

In SilverStripe through 4.5, malicious users with a valid Silverstripe CMS login (usually CMS access) can craft profile information which can lead to XSS for other users through specially crafted login form URLs.