Authenticated user with page edit permission can craft HTML, which when rendered in a page history comparison can execute client scripts.
| Software | From | Fixed in |
|---|---|---|
silverstripe / framework
|
3.4.0-rc1 | 3.4.6 |
silverstripe / framework
|
3.5.0-rc1 | 3.5.4 |