{"id":"GHSA-74j9-xhqr-6qv3","aliases":[],"url":"https://o3.security/vulnerability/GHSA-74j9-xhqr-6qv3","summary":"Reflected Cross Site Scripting (XSS) in error message","details":"If a website has been set to the \"dev\" environment mode, a URL can be provided which includes an XSS payload which will be executed in the resulting error message.","published":"2025-01-23T18:01:26Z","modified":"2025-01-23T18:08:18.367148Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"silverstripe/framework","fixedVersion":"5.3.8"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/framework/SS-2024-002.yaml"},{"type":"PACKAGE","url":"https://github.com/silverstripe/silverstripe-framework"},{"type":"WEB","url":"https://www.silverstripe.org/download/security-releases/ss-2024-002"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-01-23T18:08:18.367148Z"}}