296,746
Total vulnerabilities in the database
A cross-site scripting vulnerability has been discovered in the TreeDropdownField and TreeMultiSelectField.
This vulnerability can only be exploited if a user with CMS access has posted malicious or unescaped HTML into any of the dataobjects used as a data source for either of these fields.
This has been resolved by ensuring that all dataobjects used as a data source have their content safely encoded.
| Software | From | Fixed in |
|---|---|---|
silverstripe / framework
|
3.1.0 | 3.1.10 |