silverstripe-framework/docs/en
Serge Latyntcev ad1b00ec7d [CVE-2019-19325] XSS through non-scalar FormField attributes
Silverstripe Forms allow malicious HTML or JavaScript to be inserted
through non-scalar FormField attributes, which allows performing XSS (Cross-Site Scripting)
on some forms built with user input (Request data). This can lead to phishing attempts
to obtain a user's credentials or other sensitive user input.
There is no known attack vector for extracting user-session information or credentials automatically,
it required a user to fall for the phishing attempt.
XSS can also be used to modify the presentation of content in malicious ways.
2020-02-17 09:58:29 +13:00
..
_images Mention versioned snapshots in the versions documentation (#9057) 2019-06-16 23:52:30 +12:00
00_Getting_Started Merge branch '4.3' into 4.4 2019-06-10 17:32:07 +12:00
01_Lessons DOCS Updating "lesson 0" to a relevant link 2019-02-22 16:33:51 +13:00
02_Developer_Guides [CVE-2019-19325] XSS through non-scalar FormField attributes 2020-02-17 09:58:29 +13:00
03_Upgrading DOCS: Add docs for versioned files migration 2019-09-24 16:04:22 +12:00
04_Changelogs [CVE-2019-19325] XSS through non-scalar FormField attributes 2020-02-17 09:58:29 +13:00
05_Contributing DOCS Limited "critical security fixes" release lines 2019-04-01 17:08:13 +13:00
index.md DOCS Replaced references to core mailinglist with forum 2018-12-19 10:20:46 +13:00