First published: Wed Apr 28 2010(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in SilverStripe before 2.3.5 allow remote attackers to inject arbitrary web script or HTML via (1) the CommenterURL parameter to PostCommentForm, and in the Forum module before 0.2.5 in SilverStripe before 2.3.5 allow remote attackers to inject arbitrary web script or HTML via (2) the Search parameter to forums/search (aka the search script).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SilverStripe CMS | =2.3.0-rc2 | |
SilverStripe CMS | =2.1.0 | |
SilverStripe CMS | =2.2.0 | |
SilverStripe CMS | =2.3.1-rc2 | |
SilverStripe CMS | =2.3.0-rc3 | |
SilverStripe CMS | =2.3.3 | |
SilverStripe CMS | =2.2.2 | |
SilverStripe CMS | =2.0.0 | |
SilverStripe CMS | =2.3.1 | |
SilverStripe CMS | =2.2.4 | |
SilverStripe CMS | =2.3.1-rc1 | |
SilverStripe CMS | =2.2.1 | |
SilverStripe CMS | =2.1.1 | |
SilverStripe CMS | <=2.3.4 | |
SilverStripe CMS | =2.0.2 | |
SilverStripe CMS | =2.3.0 | |
SilverStripe CMS | =2.0.1 | |
SilverStripe CMS | =2.3.2 | |
SilverStripe CMS | =2.3.0-rc1 | |
composer/silverstripe/framework | <2.3.5 | 2.3.5 |
composer/silverstripe/cms | <2.3.5 | 2.3.5 |
<=2.3.4 | ||
=2.0.0 | ||
=2.0.1 | ||
=2.0.2 | ||
=2.1.0 | ||
=2.1.1 | ||
=2.2.0 | ||
=2.2.1 | ||
=2.2.2 | ||
=2.2.4 | ||
=2.3.0 | ||
=2.3.0-rc1 | ||
=2.3.0-rc2 | ||
=2.3.0-rc3 | ||
=2.3.1 | ||
=2.3.1-rc1 | ||
=2.3.1-rc2 | ||
=2.3.2 | ||
=2.3.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-1593 has a medium severity rating due to its potential for cross-site scripting attacks.
To fix CVE-2010-1593, upgrade to SilverStripe version 2.3.5 or later, which addresses the vulnerabilities.
CVE-2010-1593 affects SilverStripe versions prior to 2.3.5, including 2.0.0 to 2.3.4.
Yes, CVE-2010-1593 could potentially allow attackers to perform actions like data theft through cross-site scripting.
Yes, CVE-2010-1593 specifically mentions vulnerabilities in the CommenterURL parameter of PostCommentForm and the Forum module before version 0.2.5.