-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from an outdated jQuery version included via Silverstripe's asset management system. The Requirements::javascript() method is responsible for including JavaScript files like jQuery. The security patch added client-side checks before jQuery initialization, indicating this function was previously used to load the vulnerable dependency without proper input validation. While the actual XSS occurs client-side, this server-side function appears in the execution path when serving the vulnerable jQuery resource.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| silverstripe/admin | composer | >= 1.0.0, < 1.11.3 | 1.11.3 |
KEV Misses 88% of Exploited CVEs- Get the report