header-logo
Suggest Exploit
vendor:
SilverStripe CMS
by:
Sense of Security
5,5
CVSS
MEDIUM
Stored Cross-Site Scripting (XSS) and Cross-Site Request Forgeries (CSRF)
79 (XSS) and 352 (CSRF)
CWE
Product Name: SilverStripe CMS
Affected Version From: 3.0.2
Affected Version To: 3.0.2
Patch Exists: YES
Related CWE: CVE - not yet assigned
CPE: a:silverstripe:silverstripe_cms
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2012

Sense of Security – Security Advisory – SOS-12-011

SilverStripe CMS is vulnerable to a stored Cross-Site Scripting (XSS) vulnerability and Cross-Site Request Forgeries (CSRF). The site title field in the configuration page fails to securely output encode stored values. As a result, an authenticated attacker can trigger the application to store a malicious string by entering the values into the site title field. When a user visits the web site, the malicious code will be executed in the client browser. The privilege escalation is possible because the form used to change user account passwords does not require the user to confirm their current password and is vulnerable to CSRF. An attacker can reset an Administrator password by creating a malicious web site that sends a POST request to change the current user's password while they are logged into the CMS.

Mitigation:

Upgrade to version 3.0.3
Source

Exploit-DB raw data: