Silverstripe

Silverstripe

64 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.16%
  • Veröffentlicht 15.07.2020 21:15:13
  • Zuletzt bearbeitet 21.11.2024 05:35:13

SilverStripe 4.5.0 allows attackers to read certain records that should not have been placed into a result set. This affects silverstripe/recipe-cms. The automatic permission-checking mechanism in the silverstripe/graphql module does not provide comp...

  • EPSS 0.7%
  • Veröffentlicht 15.07.2020 21:15:13
  • Zuletzt bearbeitet 21.11.2024 05:35:13

In SilverStripe through 4.5.0, a specific URL path configured by default through the silverstripe/framework module can be used to disclose the fact that a domain is hosting a Silverstripe application. There is no disclosure of the specific version. T...

  • EPSS 0.21%
  • Veröffentlicht 15.07.2020 19:15:11
  • Zuletzt bearbeitet 21.11.2024 04:34:34

Silverstripe CMS sites through 4.4.4 which have opted into HTTP Cache Headers on responses served by the framework's HTTP layer can be vulnerable to web cache poisoning. Through modifying the X-Original-Url and X-HTTP-Method-Override headers, respons...

  • EPSS 0.39%
  • Veröffentlicht 15.04.2020 21:15:36
  • Zuletzt bearbeitet 21.11.2024 05:40:20

In SilverStripe through 4.5, files uploaded via Forms to folders migrated from Silverstripe CMS 3.x may be put to the default "/Uploads" folder instead. This affects installations which allowed upload folder protection via the optional silverstripe/s...

  • EPSS 0.2%
  • Veröffentlicht 19.02.2020 17:15:11
  • Zuletzt bearbeitet 21.11.2024 04:22:50

In SilverStripe through 4.3.3, the previous fix for SS-2018-007 does not completely mitigate the risk of CSRF in GraphQL mutations,

  • EPSS 0.16%
  • Veröffentlicht 19.02.2020 17:15:10
  • Zuletzt bearbeitet 21.11.2024 04:22:28

SilverStripe through 4.3.3 allows a Denial of Service on flush and development URL tools.

  • EPSS 0.36%
  • Veröffentlicht 17.02.2020 20:15:11
  • Zuletzt bearbeitet 21.11.2024 04:34:34

SilverStripe through 4.4.x before 4.4.5 and 4.5.x before 4.5.2 allows Reflected XSS on the login form and custom forms. Silverstripe Forms allow malicious HTML or JavaScript to be inserted through non-scalar FormField attributes, which allows perform...

  • EPSS 0.3%
  • Veröffentlicht 26.09.2019 16:15:11
  • Zuletzt bearbeitet 21.11.2024 04:30:39

In the Versioned Files module through 2.0.3 for SilverStripe 3.x, unpublished versions of files are publicly exposed to anyone who can guess their URL. This guess could be highly informed by a basic understanding of the symbiote/silverstripe-versione...

  • EPSS 0.34%
  • Veröffentlicht 26.09.2019 12:15:11
  • Zuletzt bearbeitet 21.11.2024 04:26:20

In SilverStripe assets 4.0, there is broken access control on files.

  • EPSS 0.35%
  • Veröffentlicht 26.09.2019 12:15:11
  • Zuletzt bearbeitet 21.11.2024 04:26:20

In SilverStripe asset-admin 4.0, there is XSS in file titles managed through the CMS.