Unrated severityNVD Advisory· Published Feb 2, 2012· Updated Apr 29, 2026
CVE-2012-0976
CVE-2012-0976
Description
Cross-site scripting (XSS) vulnerability in admin/EditForm in SilverStripe 2.4.6 allows remote authenticated users with Content Authors privileges to inject arbitrary web script or HTML via the Title parameter. NOTE: some of these details are obtained from third party information.
Affected products
1- cpe:2.3:a:silverstripe:silverstripe:2.4.6:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
11- packetstormsecurity.org/files/view/109210/silverstripecmspage-xss.txtnvdExploit
- secunia.com/advisories/47812nvdVendor Advisory
- doc.silverstripe.org/framework/en/trunk/changelogs/2.3.13nvd
- doc.silverstripe.org/framework/en/trunk/changelogs/2.4.7nvd
- osvdb.org/78677nvd
- www.openwall.com/lists/oss-security/2012/04/30/3nvd
- www.securityfocus.com/bid/51761nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/72820nvd
- github.com/silverstripe/sapphire/commit/252e187nvd
- github.com/silverstripe/sapphire/commit/475e077nvd
- github.com/silverstripe/sapphire/commit/5fe7091nvd
News mentions
0No linked articles in our index yet.