- EPSS 0.3%
- Veröffentlicht 26.09.2019 12:15:11
- Zuletzt bearbeitet 21.11.2024 04:23:11
In SilverStripe through 4.3.3, there is access escalation for CMS users with limited access through permission cache pollution.
CVE-2019-12245
- EPSS 0.26%
- Veröffentlicht 25.09.2019 19:15:10
- Zuletzt bearbeitet 21.11.2024 04:22:28
SilverStripe through 4.3.3 has incorrect access control for protected files uploaded via Upload::loadIntoFile(). An attacker may be able to guess a filename in silverstripe/assets via the AssetControlExtension.
CVE-2019-12205
- EPSS 0.38%
- Veröffentlicht 25.09.2019 19:15:10
- Zuletzt bearbeitet 21.11.2024 04:22:24
SilverStripe through 4.3.3 has Flash Clipboard Reflected XSS.
CVE-2019-12204
- EPSS 0.83%
- Veröffentlicht 25.09.2019 19:15:10
- Zuletzt bearbeitet 21.11.2024 04:22:24
In SilverStripe through 4.3.3, a missing warning about leaving install.php in a public webroot can lead to unauthenticated admin access.
CVE-2019-12203
- EPSS 0.05%
- Veröffentlicht 25.09.2019 19:15:10
- Zuletzt bearbeitet 21.11.2024 04:22:24
SilverStripe through 4.3.3 allows session fixation in the "change password" form.
CVE-2019-5715
- EPSS 0.32%
- Veröffentlicht 11.04.2019 19:29:01
- Zuletzt bearbeitet 21.11.2024 04:45:22
All versions of SilverStripe 3 prior to 3.6.7 and 3.7.3, and all versions of SilverStripe 4 prior to 4.0.7, 4.1.5, 4.2.4, and 4.3.1 allows Reflected SQL Injection through Form and DataObject.
CVE-2017-18049
- EPSS 0.21%
- Veröffentlicht 23.01.2018 06:29:00
- Zuletzt bearbeitet 21.11.2024 03:19:15
In the CSV export feature of SilverStripe before 3.5.6, 3.6.x before 3.6.3, and 4.x before 4.0.1, it's possible for the output to contain macros and scripts, which may be executed if imported without sanitization into common software (including Micro...
CVE-2017-12849
- EPSS 0.23%
- Veröffentlicht 12.10.2017 15:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Response discrepancy in the login and password reset forms in SilverStripe CMS before 3.5.5 and 3.6.x before 3.6.1 allows remote attackers to enumerate users via timing attacks.
CVE-2017-14498
- EPSS 0.38%
- Veröffentlicht 15.09.2017 18:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
SilverStripe CMS before 3.6.1 has XSS via an SVG document that is mishandled by (1) the Insert Media option in the content editor or (2) an admin/assets/add pathname, as demonstrated by the admin/pages/edit/EditorToolbar/MediaForm/field/AssetUploadFi...
CVE-2017-5197
- EPSS 0.27%
- Veröffentlicht 06.03.2017 06:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
There is XSS in SilverStripe CMS before 3.4.4 and 3.5.x before 3.5.2. The attack vector is a page name. An example payload is a crafted JavaScript event handler within a malformed SVG element.