CVE-2024-47605
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Jan 14, 2025
CWE ID 79
Summary
CVE-2024-47605 is a vulnerability affecting the silverstripe-asset-admin package for SilverStripe CMS. The "insert media" function, which allows users to embed media into their content, inadvertently replaces oEmbed JSON shortcodes with unfiltered HTML. Maliciously crafted HTML can inject scripts, posing a threat to both the CMS and the website's front-end. Affected users are strongly advised to upgrade to SilverStripe framework version 5.3.8 to mitigate this issue. At present, there are no known workarounds for this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.