A XSS risk exists in the returnURL parameter passed to dev/build. An unvalidated url could cause the user to redirect to an unverified third party url outside of the site.
This issue is resolved in framework 3.1.14 stable release.
| Software | From | Fixed in |
|---|---|---|
silverstripe / framework
|
- | 3.1.14 |