GHSA-4q66-g4mm-8rg5

    Dashboard / Vulnerabilities / GHSA-4q66-g4mm-8rg5

    GHSA-4q66-g4mm-8rg5

    Published: 31 Jul 2023Last Modified: 2 Dec 2024

    Summary: Silverstripe has Cross-site Scripting (XSS) vulnerabilities inherited from TinyMCE

    Details: TinyMCE 4.x is vulnerable to several XSS vectors, which had been patched in later versions. Two of these have been identified as affecting `silverstripe/admin`. Only Silverstripe CMS 4 is affected by this issue. It's not possible to upgrade Silverstripe CMS 4 to use a more recent release of TinyMCE without introducing breaking changes. Instead, the security patches that shipped in later releases of TinyMCE have been backported to the TinyMCE version bundled in `silverstripe/admin`. Silverstripe CMS 5 is not affected by those vulnerabilities because it uses TinyMCE 6. You can find more information about the underlying vulnerabilities in those GitHub security advisories: - [GHSA-5h9g-x5rv-25wg Cross-site scripting vulnerability in TinyMCE](https://github.com/advisories/GHSA-5h9g-x5rv-25wg) - [GHSA-w7jx-j77m-wp65 Cross-site scripting vulnerability in TinyMCE](https://github.com/advisories/GHSA-w7jx-j77m-wp65)

    Affected packages

    Package

    Name: silverstripe/admin

    Purl: pkg:composer/silverstripe/admin

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.13.6

    Affected versions

    1.0.0
    1.0.0-alpha6
    1.0.0-alpha7
    1.0.0-beta1
    1.0.0-beta2
    1.0.0-beta3
    1.0.0-beta4
    1.0.0-rc1
    1.0.0-rc2
    1.0.0-rc3
    1.0.1
    1.0.1-rc1
    1.0.2
    1.0.3
    1.0.4
    1.0.5
    1.0.6
    1.0.7

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-4q66-g4mm-8rg5 | CVE-DB