GHSA-xgpf-p52j-pf7m
Dashboard / Vulnerabilities / GHSA-xgpf-p52j-pf7m
Summary: XSS in CreateQueuedJobTask
Details: A vulnerability has been identified in the Silverstripe CMS 3 and 4 version of the symbiote/silverstripe-queuedjobs module. A Cross Site Scripting vulnerability allows an attacker to inject an arbitrary payload in the CreateQueuedJobTask dev task via a specially crafted URL.
References: https://nvd.nist.gov/vuln/detail/CVE-2021-27938, https://github.com/FriendsOfPHP/security-advisories/blob/master/symbiote/silverstripe-queuedjobs/CVE-2021-27938.yaml, https://github.com/symbiote/silverstripe-queuedjobs/releases, https://www.silverstripe.org/download/security-releases/cve-2021-27938
Affected packages
Package
Name: symbiote/silverstripe-queuedjobs
Purl: pkg:composer/symbiote/silverstripe-queuedjobs
Affected ranges
Type: ECOSYSTEM
Events:
