CVE-2017-14498: Silverstripe

Medium severity, CVSS 6.1. EPSS: 1.3% chance of exploitation in the next 30 days.

SilverStripe CMS before 3.6.1 has XSS via an SVG document that is mishandled by (1) the Insert Media option in the content editor or (2) an admin/assets/add pathname, as demonstrated by the admin/pages/edit/EditorToolbar/MediaForm/field/AssetUploadField/upload URI, aka issue SS-2017-017.

Affected products

Published 2017-09-15. Last modified 2026-06-17.