Silverstripe silverstripe/framework through 4.11 allows XSS (issue 1 of 2) via JavaScript payload to the href attribute of a link by splitting a javascript URL with white space characters.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| silverstripe/framework(Packagist) | 4.0.0 | 4.11.13 | N/A |
CVSS Metrics