CVE-2025-25197

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-25197
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-25197.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-25197
Aliases
Published
2025-04-10T13:15:51Z
Modified
2025-04-11T16:50:50.555334Z
Summary
[none]
Details

Silverstripe Elemental extends a page type to swap the content area for a list of manageable elements to compose a page out of rather than a single text field. An elemental block can include an XSS payload, which can be executed when viewing the "Content blocks in use" report. The vulnerability is specific to that report and is a result of failure to cast input prior to including it in the grid field. This vulnerability is fixed in 5.3.12.

References

Affected packages

Git / github.com/silverstripe/silverstripe-elemental

Affected ranges

Type
GIT
Repo
https://github.com/silverstripe/silverstripe-elemental
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

1.*

1.0.0
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.9.0

2.*

2.0.0
2.0.0-beta1
2.0.1
2.1.0
2.1.1
2.1.2

3.*

3.0.0
3.0.0-beta1
3.0.0-beta2
3.0.0-beta3
3.0.0-rc1
3.0.0-rc2
3.0.1
3.0.2
3.1.0
3.1.1

4.*

4.0.0
4.0.0-beta1
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.10.0
4.10.0-beta1
4.10.0-rc1
4.10.1
4.10.2
4.11.0
4.11.0-beta1
4.11.0-rc1
4.11.1
4.11.2
4.11.3
4.11.4
4.11.5
4.11.6
4.11.7
4.11.8
4.11.9
4.2.0
4.2.0-beta1
4.2.1
4.3.0
4.3.1
4.3.2
4.4.0
4.4.0-rc1
4.4.1
4.5.0
4.6.0
4.6.0-beta1
4.6.0-beta2
4.6.0-rc1
4.7.0
4.7.1
4.8.0
4.8.0-beta1
4.8.0-rc1
4.8.1
4.8.2
4.8.3
4.9.0
4.9.0-beta1
4.9.0-rc1
4.9.1
4.9.2
4.9.3
4.9.4

5.*

5.0.0
5.0.0-alpha1
5.0.0-alpha2
5.0.0-alpha3
5.0.0-beta1
5.0.0-beta2
5.0.0-rc1
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-beta1
5.1.0-rc1
5.1.1
5.1.2
5.1.3
5.1.4
5.1.5
5.2.0
5.2.0-beta1
5.2.0-rc1
5.2.1
5.2.2
5.2.3
5.2.4
5.3.0
5.3.0-beta1
5.3.0-rc1
5.3.1
5.3.10
5.3.11
5.3.2
5.3.3
5.3.4
5.3.5
5.3.6
5.3.7
5.3.8
5.3.9