Impact
The vulnerability is a cross‑site scripting issue in the Silverstripe Framework's media‑embed feature (CWE‑79). A specially crafted embed can inject arbitrary JavaScript that will execute in a user’s browser when the content is rendered. This flaw allows an attacker to run code in the context of the page viewed by a user.
Affected Systems
All installations of the Silverstripe Framework older than version 6.2.2 are vulnerable. Any site that relies on the affected framework versions is at risk.
Risk and Exploitability
The CVSS score of 5.4 classifies the vulnerability as moderate. The EPSS score of <1% indicates a low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is inferred to be a content author or administrator who can embed web media, as described in the advisory. The vulnerable code was removed in version 6.2.2, so the flaw can be exploited only against unpatched installations.
OpenCVE Enrichment