CVE-2020-25817
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
SilverStripe through 4.6.0-rc1 has an XXE Vulnerability in CSSContentParser. A developer utility meant for parsing HTML within unit tests can be vulnerable to XML External Entity (XXE) attacks. When this developer utility is misused for purposes involving external or user submitted data in custom project code, it can lead to vulnerabilities such as XSS on HTML output rendered through this custom code. This is now mitigated by disabling external entities during parsing. (The correct CVE ID year is 2020 [CVE-2020-25817, not CVE-2021-25817]).
SilverStripe versiones hasta 4.6.0-rc1, presenta una vulnerabilidad de tipo XXE en CSSContentParser. Una utilidad para desarrolladores destinada a analizar HTML dentro de las pruebas unitarias puede ser vulnerable a ataques de tipo XML External Entity (XXE). Cuando esta utilidad para desarrolladores es usada de forma indebida para fines que implican datos externos o enviados por el usuario en el código de proyectos personalizados, puede conllevar a vulnerabilidades de tipo XSS en la salida de HTML renderizada mediante este código personalizado. Esto es mitigado ahora al desactivar las entidades externas durante el análisis sintáctico. (El año correcto del CVE ID es 2020 [CVE-2020-25817, no CVE-2021-25817])
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-09-23 CVE Reserved
- 2021-06-08 CVE Published
- 2023-09-12 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-611: Improper Restriction of XML External Entity Reference
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://www.silverstripe.org/download/security-releases/cve-2020-25817 | Broken Link |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://forum.silverstripe.org/c/releases | 2021-06-17 | |
https://www.silverstripe.org/blog/tag/release | 2021-06-17 | |
https://www.silverstripe.org/download/security-releases | 2021-06-17 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Silverstripe Search vendor "Silverstripe" | Silverstripe Search vendor "Silverstripe" for product "Silverstripe" | < 4.6.0 Search vendor "Silverstripe" for product "Silverstripe" and version " < 4.6.0" | - |
Affected
| ||||||
Silverstripe Search vendor "Silverstripe" | Silverstripe Search vendor "Silverstripe" for product "Silverstripe" | 4.6.0 Search vendor "Silverstripe" for product "Silverstripe" and version "4.6.0" | rc1 |
Affected
|