| Main Archive Page > Month Archives > full-disclosure-uk archives |
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Silverstripe CMS, <http://silverstripe.org/>, version 2.3.4 and lower (and its unreleased 2.4 branch), is vulnerable to two Cross Site Scripting issues.
According to its quickly responding developers, Silverstripe version
2.3.5 fixes both issues:
http://groups.google.com/group/silverstripe-announce/browse_thread/thread/f51749342eee9456
Relevant SCM changesets:
http://open.silverstripe.org/changeset/97034
http://open.silverstripe.org/changeset/97070
http://open.silverstripe.org/changeset/97073
http://open.silverstripe.org/changeset/97074
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)
iEYEAREKAAYFAktZ9qEACgkQn6GkvSd/BgzVmACfaNiygTiaMy59QygEu0xeZ93S
KzsAoIIQA7krAVdNycjXdh7EaIMUiVk+
=9I4y
-----END PGP SIGNATURE-----