CVE-2010-4823
Last modified
CVE-2010-4823 is a vulnerability of currently unknown severity. Cross-site scripting (XSS) vulnerability in the httpError method in sapphire/core/control/RequestHandler.php in SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4, when custom error handling is not used, allows remote attackers to inject arbitrary web script or HTML via "missing URL actions.". EPSS estimates a 1.73% chance of exploitation in the next 30 days.
Description
Cross-site scripting (XSS) vulnerability in the httpError method in sapphire/core/control/RequestHandler.php in SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4, when custom error handling is not used, allows remote attackers to inject arbitrary web script or HTML via "missing URL actions."
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Silverstripe | Silverstripe | 2.3.0 |
| Silverstripe | Silverstripe | 2.3.1 |
| Silverstripe | Silverstripe | 2.3.2 |
| Silverstripe | Silverstripe | 2.3.3 |
| Silverstripe | Silverstripe | 2.3.4 |
| Silverstripe | Silverstripe | 2.3.5 |
| Silverstripe | Silverstripe | 2.3.6 |
| Silverstripe | Silverstripe | 2.3.7 |
| Silverstripe | Silverstripe | 2.3.8 |
| Silverstripe | Silverstripe | 2.3.9 |
| Silverstripe | Silverstripe | 2.4.0 |
| Silverstripe | Silverstripe | 2.4.1 |
| Silverstripe | Silverstripe | 2.4.2 |
| Silverstripe | Silverstripe | 2.4.3 |
References
- http://doc.silverstripe.org/framework/en/trunk/changelogs//2.4.4Exploit, Patch, Vendor Advisory
- http://open.silverstripe.org/changeset/114444Exploit, Patch
- http://secunia.com/advisories/42346Vendor Advisory
- http://doc.silverstripe.org/framework/en/trunk/changelogs//2.4.4Exploit, Patch, Vendor Advisory
- http://open.silverstripe.org/changeset/114444Exploit, Patch
- http://secunia.com/advisories/42346Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-4823?
How severe is CVE-2010-4823?
How do I fix CVE-2010-4823?
Are you affected by CVE-2010-4823?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
