In SilverStripe through 4.5, malicious users with a valid Silverstripe CMS login (usually CMS access) can craft profile information which can lead to XSS for other users through specially crafted login form URLs.
{
"severity": "Medium",
"cpes": [
"cpe:2.3:a:silverstripe:silverstripe:*:*:*:*:*:*:*:*"
]
}