Medium severity6.1NVD Advisory· Published Feb 17, 2020· Updated Jun 17, 2026
CVE-2019-19325
CVE-2019-19325
Description
SilverStripe through 4.4.x before 4.4.5 and 4.5.x before 4.5.2 allows Reflected XSS on the login form and custom forms. Silverstripe Forms allow malicious HTML or JavaScript to be inserted through non-scalar FormField attributes, which allows performing XSS (Cross-Site Scripting) on some forms built with user input (Request data). This can lead to phishing attempts to obtain a user's credentials or other sensitive user input.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
silverstripe/frameworkPackagist | >= 4.5.0, < 4.5.2 | 4.5.2 |
silverstripe/frameworkPackagist | >= 4.0.0, < 4.4.5 | 4.4.5 |
Affected products
3- SilverStripe/SilverStripedescription
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-qvrv-2x7x-78x2ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-19325ghsaADVISORY
- www.silverstripe.org/download/security-releases/cve-2019-19325nvdVendor AdvisoryWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/framework/CVE-2019-19325.yamlghsaWEB
- github.com/silverstripe/silverstripe-framework/commit/49fda52b12ba59f0a04bcabf78425586a8779e89ghsaWEB
News mentions
0No linked articles in our index yet.