PT-2024-25029 · Silverstripe · Silverstripe/Framework

·

CVE-2024-32981

·

Published

2024-07-17

·

Updated

2025-09-04

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Silverstripe framework versions prior to 5.2.16
Description A bad actor with access to edit content in the CMS could send a specifically crafted encoded payload to the server, which could be used to inject a JavaScript payload on the front end of the site. The payload would be sanitised on the client-side, but server-side sanitisation doesn't catch it.
Recommendations For versions prior to 5.2.16, upgrade to version 5.2.16 or later to resolve the issue. At the moment, there is no information about other workarounds for this vulnerability.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-32981
GHSA-CHX7-9X8H-R5MG

Affected Products

Silverstripe/Framework