{"id":"GHSA-jxcx-3h54-qqxx","aliases":[],"url":"https://o3.security/vulnerability/GHSA-jxcx-3h54-qqxx","summary":"SilverStripe CMS Cross-site Scripting vulnerabilities inherited from TinyMCE","details":"TinyMCE 4.x is vulnerable to several XSS vectors, which had been patched in later versions. Two of these have been identified as affecting silverstripe/admin.\n\nOnly Silverstripe CMS 4 is affected by these vulnerabilities. It's not possible to upgrade Silverstripe CMS 4 to use a more recent release of TinyMCE without introducing breaking changes. Instead, the security patches that shipped in later releases of TinyMCE have been backported to the TinyMCE version bundled in silverstripe/admin.\n\nSilverstripe CMS 5 is not affected by these vulnerabilities because it uses TinyMCE 6.","published":"2023-08-23T19:43:56Z","modified":"2024-11-29T05:39:32.067990Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"silverstripe/admin","fixedVersion":"1.13.6"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/admin/SS-2023-002.yaml"},{"type":"PACKAGE","url":"https://github.com/silverstripe/silverstripe-admin"},{"type":"WEB","url":"https://www.silverstripe.org/download/security-releases/SS-2023-002"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-11-29T05:39:32.067990Z"}}