First published: Tue Mar 16 2021(Updated: )
A vulnerability has been identified in the Silverstripe CMS 3 and 4 version of the symbiote/silverstripe-queuedjobs module. A Cross Site Scripting vulnerability allows an attacker to inject an arbitrary payload in the CreateQueuedJobTask dev task via a specially crafted URL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/symbiote/silverstripe-queuedjobs | >=3.0.0<3.0.2>=3.1.0<3.1.4>=4.0.0<4.0.7>=4.1.0<4.1.2>=4.2.0<4.2.4>=4.3.0<4.3.3>=4.4.0<4.4.3>=4.5.0<4.5.1>=4.6.0<4.6.4 | |
Symbiote Silverstripe Queued Jobs | >=3.0.0<3.0.2 | |
Symbiote Silverstripe Queued Jobs | >=3.1.0<3.1.4 | |
Symbiote Silverstripe Queued Jobs | >=4.0.0<4.0.7 | |
Symbiote Silverstripe Queued Jobs | >=4.1.0<4.1.2 | |
Symbiote Silverstripe Queued Jobs | >=4.2.0<4.2.4 | |
Symbiote Silverstripe Queued Jobs | >=4.3.0<4.3.3 | |
Symbiote Silverstripe Queued Jobs | >=4.4.0<4.4.3 | |
Symbiote Silverstripe Queued Jobs | >=4.5.0<4.5.1 | |
Symbiote Silverstripe Queued Jobs | >=4.6.0<4.6.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-27938 is a Cross Site Scripting (XSS) vulnerability in the CreateQueuedJobTask dev task of the symbiote/silverstripe-queuedjobs module in Silverstripe CMS 3 and 4.
CVE-2021-27938 has a severity rating of 6.1 (medium).
CVE-2021-27938 affects the symbiote/silverstripe-queuedjobs module in Silverstripe CMS 3 and 4.
To fix CVE-2021-27938, update to a version of the symbiote/silverstripe-queuedjobs module that is not affected by the vulnerability.
More information about CVE-2021-27938 can be found at the following references: [Silverstripe Security Advisory](https://www.silverstripe.org/download/security-releases/cve-2021-27938) and [GitHub release](https://github.com/symbiote/silverstripe-queuedjobs/releases).