silverstripe/framework Security Advisories (82)
-
[MEDIUM] CVE-2023-48714 Record titles for restricted records can be viewed if exposed by GridFieldAddExistingAutocompleter
PKSA-vcdc-4796-kn58 CVE-2023-48714 GHSA-qm2j-qvq3-j29v
Affected version: >=3.0.0,<4.0.0|>=4.0.0,<4.13.39|>=5.0.0,<5.1.11
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[LOW] CVE-2023-32302 - Members with no password can be created and bypass custom login forms
PKSA-2t2m-vnwy-55q7 CVE-2023-32302 GHSA-36xx-7vf6-7mv3
Affected version: >=3.0.0,<4.13.14|>=5.0.0,<5.0.13
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[MEDIUM] CVE-2023-22729 - Open redirect vulnerability on CMSSecurity relogin screen
PKSA-hkbw-7cv6-kp2b CVE-2023-22729 GHSA-fw84-xgm8-9jmv
Affected version: >=4.0.0,<4.12.5
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[MEDIUM] CVE-2023-22728 - Missing permission check in GridFieldPrintButton
PKSA-r31r-w74j-z58p CVE-2023-22728 GHSA-jh3w-6jp2-vqqm
Affected version: >=4.0.0,<4.12.5
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[MEDIUM] CVE-2022-25238: Stored XSS via HTML fields
PKSA-pwy1-2c1j-9m7p CVE-2022-25238 GHSA-jx34-gqqq-r6gm
Affected version: >=4.0.0,<4.10.9
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[MEDIUM] CVE-2022-28803: Stored XSS in link tags added via XHR
PKSA-d1c8-bxwg-9sbf CVE-2022-28803 GHSA-rppc-655v-7j3c
Affected version: >=4.0.0,<4.10.9
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[MEDIUM] CVE-2021-41559: Quadratic blowup in Convert::xml2array()
PKSA-9b8c-khwh-k6t3 CVE-2021-41559 GHSA-9fmg-89fx-r33w
Affected version: >=4.0.0,<4.10.9
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[MEDIUM] Silverstripe XSS Vulnerabilities
PKSA-b2bh-3nd5-4ft2 CVE-2012-4968 GHSA-v358-rvxr-wffx
Affected version: >=2.4,<2.4.7|>=2.3,<2.3.13
Reported by:
GitHub -
[MEDIUM] Silverstripe CMS Open Redirect
PKSA-ktdv-zx9y-ctn1 CVE-2015-5062 GHSA-fh35-p8ph-p545
Affected version: <=3.1.13
Reported by:
GitHub -
[MEDIUM] Business Logic Errors in SilverStripe Framework
PKSA-7j38-hj68-r82v CVE-2022-0227 GHSA-32m2-9f76-4gv8
Affected version: <4.10.1
Reported by:
GitHub -
[MEDIUM] CVE-2022-38462 - Reflected XSS in querystring parameters
PKSA-w2s3-shwy-3fdb CVE-2022-38462 GHSA-vvxf-r4vm-2vm6
Affected version: >=4.0.0,<4.11.13
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[HIGH] CVE-2022-38148 - Blind SQL Injection via GridFieldSortableHeader
PKSA-66v9-dz78-mbvh CVE-2022-38148 GHSA-rr8h-f97q-8p9c
Affected version: >=4.0.0,<4.10.11|>=4.11.0,<4.11.14
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[MEDIUM] CVE-2022-38724 - XSS in shortcodes
PKSA-nv1s-bg97-dttr CVE-2022-38724 GHSA-9cx2-hj6m-fv58
Affected version: >=4.0.0,<4.11.13
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[MEDIUM] CVE-2022-37430 - Stored XSS using uppercase characters in HTMLEditor
PKSA-vhcz-xnb3-24gr CVE-2022-37430 GHSA-qw4w-vq8v-2wcv
Affected version: >=4.0.0,<4.11.13
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[MEDIUM] CVE-2022-37429 - Stored XSS using HTMLEditor
PKSA-6c76-jv2c-jdb2 CVE-2022-37429 GHSA-wc6r-4ggc-79w5
Affected version: >=4.0.0,<4.11.13
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[MEDIUM] CVE-2020-26138 FormField: with square brackets in field name skips validation
PKSA-pq7g-1pwh-dw3n CVE-2020-26138 GHSA-7mv4-4xpg-xq44
Affected version: >=3.0.0,<4.0.0|>=4.0.0,<4.7.4
Reported by:
GitHub, FriendsOfPHP/security-advisories -
CVE-2021-25817 XXE: Vulnerability in CSSContentParser
PKSA-pkf7-4y19-7jgw CVE-2021-25817
Affected version: >=4.0.0,<4.7.4
Reported by:
FriendsOfPHP/security-advisories -
[MEDIUM] CVE-2020-9311: Malicious user profile information can cause login form XSS
PKSA-34vk-6svm-bpgy CVE-2020-9311 GHSA-2pw2-qpcp-m47x
Affected version: >=3.0.0,<3.7.5
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[HIGH] CVE-2020-6164: Information disclosure on /interactive URL path
PKSA-zhcm-grw1-sw1m CVE-2020-6164 GHSA-gm5x-hpmw-xpxg
Affected version: >=4.0.0,<4.4.7|>=4.5.0,<4.5.4
Reported by:
GitHub, FriendsOfPHP/security-advisories -
CVE-2019-19326: Web Cache Poisoning through HTTPRequestBuilder
PKSA-75gp-x5bj-hcwc CVE-2019-19326
Affected version: >=4.0.0,<4.4.7|>=4.5.0,<4.5.4|>=3.0.0,<3.7.5
Reported by:
FriendsOfPHP/security-advisories -
[MEDIUM] CVE-2019-19325: XSS through non-scalar FormField attributes
PKSA-cttv-q8kk-m71w CVE-2019-19325 GHSA-qvrv-2x7x-78x2
Affected version: >=4.0.0,<4.4.5|>=4.5.0,<4.5.2
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[MEDIUM] Lack of access control on upoaded files
PKSA-5yvt-vswv-zn54 CVE-2019-12245 GHSA-jvx5-rm6q-gx7p
Affected version: >=4.4.0,<4.4.4|>=4.0.0,<4.3.6|>=3.7.0,<3.7.4|<3.6.8
Reported by:
GitHub -
[MEDIUM] CVE-2019-12205: Clipboard Reflected XSS
PKSA-89c6-sr3z-fq77 CVE-2019-12205 GHSA-rfvw-5848-gxc5
Affected version: >=3.0.0,<3.9.99|>=4.3.0,<4.3.5|>=4.4.0,<4.4.4
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[LOW] CVE-2019-12617: Access escalation for CMS users with limited access through permission cache pollution
PKSA-5rys-h48p-tw2m CVE-2019-12617 GHSA-6r58-4xgr-gm6m
Affected version: >=4.3.0,<4.3.5|>=4.4.0,<4.4.4
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[CRITICAL] CVE-2019-12204: Missing warning on install.php on public webroot can lead to unauthenticated admin access
PKSA-5v3s-v315-b3zz CVE-2019-12204 GHSA-cg8j-8w52-735v
Affected version: >=4.1.0,<4.3.5|>=4.4.0,<4.4.4
Reported by:
GitHub, FriendsOfPHP/security-advisories -
CVE-2019-14272: XSS in file titles managed through the CMS
PKSA-qgy1-mwbw-7ywr CVE-2019-14272
Affected version: >=4.0.0,<4.3.5|>=4.4.0,<4.4.4
Reported by:
FriendsOfPHP/security-advisories -
[MEDIUM] CVE-2019-14273: Broken Access control on files
PKSA-g9hg-jbs3-qz4m CVE-2019-14273 GHSA-43jj-2rwc-2m3f
Affected version: >=4.0.0,<4.3.5|>=4.4.0,<4.4.4
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[MEDIUM] CVE-2019-16409: Secureassets and versionedfiles modules can expose versions of protected files
PKSA-wp9q-nw9g-sv7t CVE-2019-16409 GHSA-xm6j-x342-gwq9
Affected version: >=4.0.0,<4.3.5|>=4.4.0,<4.4.4
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[MEDIUM] CVE-2019-12203: Session fixation in "change password" form
PKSA-wh2k-pccc-jn5p CVE-2019-12203 GHSA-w7r7-r8r9-vrg2
Affected version: >=3.6.0,<3.6.8|>=3.7.0,<3.7.4|>=4.0.0,<4.3.5|>=4.4.0,<4.4.4
Reported by:
GitHub, FriendsOfPHP/security-advisories -
CVE-2019-12246: Denial of Service on flush and development URL tools
PKSA-9415-sntm-q9m8 CVE-2019-12246
Affected version: >=4.0.0,<4.4.0|>=4.1.0,<4.4.0|>=4.2.0,<4.4.0|>=4.3.0,<4.4.0
Reported by:
FriendsOfPHP/security-advisories -
[CRITICAL] CVE-2019-5715: Reflected SQL Injection through Form and DataObject
PKSA-sn55-3v1d-5xkw CVE-2019-5715 GHSA-wvfw-w3x6-g526
Affected version: >=3.0.0,<3.6.7|>=3.7.0,<3.7.3|>=4.0.0,<4.0.7|>=4.1.0,<4.1.5|>=4.2.0,<4.2.4|>=4.3.0,<4.3.1
Reported by:
GitHub, FriendsOfPHP/security-advisories -
SS-2018-019: Possible denial of service attack vector when flushing
Affected version: >=4.0.0,<4.0.5|>=4.1.0,<4.1.3|>=4.2.0,<4.2.2
Reported by:
FriendsOfPHP/security-advisories -
SS-2018-020: Potential SQL vulnerability in PostgreSQL database connector
Affected version: >=4.0.0,<4.0.6|>=4.1.0,<4.1.4|>=4.2.0,<4.2.3
Reported by:
FriendsOfPHP/security-advisories -
SS-2018-018: Database credentials disclosure during connection failure
Affected version: >=3.7.0,<3.7.1|>=4.0.0,<4.0.5|>=4.1.0,<4.1.3|>=4.2.0,<4.2.2
Reported by:
FriendsOfPHP/security-advisories -
SS-2018-013: Passwords sent back to browsers under some circumstances
Affected version: >=3.5.5,<3.7.0|>=4.0.3,<4.0.4|>=4.1.0,<4.1.1
Reported by:
FriendsOfPHP/security-advisories -
SS-2018-006: Code execution vulnerability
Affected version: >=4.0.3,<4.0.4|>=4.1.0,<4.1.1
Reported by:
FriendsOfPHP/security-advisories -
SS-2018-008: BackURL validation bypass with malformed URLs
Affected version: >=4.0.0,<4.0.4|>=4.1.0,<4.1.1
Reported by:
FriendsOfPHP/security-advisories -
SS-2018-010: Member disclosure in login form
Affected version: >=4.0.0,<4.0.4|>=4.1.0,<4.1.1
Reported by:
FriendsOfPHP/security-advisories -
SS-2018-012: Uploaded PHP script execution in assets
Affected version: >=4.0.0,<4.0.4|>=4.1.0,<4.1.1
Reported by:
FriendsOfPHP/security-advisories -
SS-2018-005: isDev and isTest unguarded
Affected version: >=4.0.0,<4.0.4|>=4.1.0,<4.1.1
Reported by:
FriendsOfPHP/security-advisories -
SS-2018-014: Dangerous file types in allowed upload
Affected version: >=3.6.5,<3.6.6|>=4.0.3,<4.0.4|>=4.1.0,<4.1.1
Reported by:
FriendsOfPHP/security-advisories -
SS-2018-001: Privilege Escalation Risk in Member Edit form
Affected version: >=3.5.7,<3.5.8|>=3.6.0,<3.6.6|>=4.0.0,<4.0.4|>=4.1.0,<4.1.1
Reported by:
FriendsOfPHP/security-advisories -
SS-2017-010: install.php discloses sensitive data by pre-populating DB credential forms
Affected version: >=4.0.0,<4.0.1
Reported by:
FriendsOfPHP/security-advisories -
SS-2017-007: CSV Excel Macro Injection
Affected version: >=3.5.0,<3.5.6|>=3.6.0,<3.6.3|>=4.0.0,<4.0.1
Reported by:
FriendsOfPHP/security-advisories -
SS-2017-009: Users inadvertently passing sensitive data to LoginAttempt
Affected version: >=3.5.0,<3.5.6|>=3.6.0,<3.6.3|>=4.0.0,<4.0.1
Reported by:
FriendsOfPHP/security-advisories -
SS-2017-006: Session user agent change detection
Affected version: >=3.5.0,<3.5.6|>=3.6.0,<3.6.3
Reported by:
FriendsOfPHP/security-advisories -
SS-2017-008: SQL injection in full text search of SilverStripe 4
Affected version: >=3.5.0,<3.5.6|>=3.6.0,<3.6.3|>=4.0.0,<4.0.1
Reported by:
FriendsOfPHP/security-advisories -
SS-2017-005: User enumeration via timing attack on login and password reset forms
Affected version: >=3.5.0,<3.5.5|>=3.6.0,<3.6.2
Reported by:
FriendsOfPHP/security-advisories -
SS-2017-003: XSS in RedirectorPage
Affected version: >=3.4.0,<3.4.6|>=3.5.0,<3.5.4
Reported by:
FriendsOfPHP/security-advisories -
SS-2017-004: XSS in page history comparison
Affected version: >=3.4.0,<3.4.6|>=3.5.0,<3.5.4
Reported by:
FriendsOfPHP/security-advisories -
SS-2017-002: Member disclosure in login form
Affected version: >=3.4.0,<3.4.6|>=3.5.0,<3.5.4
Reported by:
FriendsOfPHP/security-advisories -
Reported by:
FriendsOfPHP/security-advisories -
SS-2016-010: ReadOnly transformation for formfields exploitable
Affected version: >=3.1.0,<3.1.21|>=3.2.0,<3.2.6|>=3.3.0,<3.3.4|>=3.4.0,<3.4.2
Reported by:
FriendsOfPHP/security-advisories -
SS-2016-016: XSS In CMSSecurity BackURL
Affected version: >=3.1.0,<3.1.21|>=3.2.0,<3.2.6|>=3.3.0,<3.3.4|>=3.4.0,<3.4.2
Reported by:
FriendsOfPHP/security-advisories -
SS-2016-007: VersionedRequestFilter vulnerability
Affected version: >=3.3.2,<3.3.3|>=3.4.0,<3.4.1
Reported by:
FriendsOfPHP/security-advisories -
SS-2016-005: Brute force bypass on default admin
Affected version: >=3.1.18,<3.1.19|>=3.2.3,<3.2.4|>=3.3.1,<3.3.2
Reported by:
FriendsOfPHP/security-advisories -
SS-2016-004: XSS in CMS Edit Page
Affected version: >=3.1.18,<3.1.19|>=3.2.3,<3.2.4|>=3.3.1,<3.3.2
Reported by:
FriendsOfPHP/security-advisories -
SS-2016-006: Missing CSRF protection in login form
Affected version: >=3.1.18,<3.1.19|>=3.2.3,<3.2.4|>=3.3.1,<3.3.2
Reported by:
FriendsOfPHP/security-advisories -
SS-2016-003: Hostname, IP and Protocol Spoofing through HTTP Headers
Affected version: >=3.1.0,<=3.1.16|>=3.2.0,<=3.2.1|>3.2,<3.3.0
Reported by:
FriendsOfPHP/security-advisories -
SS-2015-028: Missing security check on dev/build/defaults
Affected version: >=3.1.0,<=3.1.16|>=3.2.0,<=3.2.1|>3.2,<3.3.0
Reported by:
FriendsOfPHP/security-advisories -
SS-2016-002: CSRF vulnerability in GridFieldAddExistingAutocompleter
Affected version: >=3.1.0,<=3.1.16|>=3.2.0,<=3.2.1|>3.2,<3.3.0
Reported by:
FriendsOfPHP/security-advisories -
SS-2015-027: HtmlEditor embed url sanitisation
Affected version: >=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.2.1
Reported by:
FriendsOfPHP/security-advisories -
SS-2015-026: Form field validation message XSS vulnerability
Affected version: >=3.0.0,<3.1.0|>=3.1.0,<3.1.16|>=3.2.0,<3.2.1
Reported by:
FriendsOfPHP/security-advisories -
Reported by:
FriendsOfPHP/security-advisories -
SS-2015-015: XSS in dev/build returnURL Parameter
Affected version: >=3.1.0,<3.1.14
Reported by:
FriendsOfPHP/security-advisories -
SS-2015-013: X-Forwarded-Host request hostname injection
Affected version: >=3.1.0,<3.1.13
Reported by:
FriendsOfPHP/security-advisories -
SS-2015-014: Vulnerability on 'isDev', 'isTest' and 'flush' $_GET validation
Affected version: >=3.0.0,<=3.0.13|>=3.1.0,<3.1.13
Reported by:
FriendsOfPHP/security-advisories -
SS-2015-012: External redirection risk in Security?ReturnURL
Affected version: >=3.0.0,<=3.0.13|>=3.1.0,<=3.1.12
Reported by:
FriendsOfPHP/security-advisories -
SS-2015-011: Potential SQL Injection Vulnerability
Affected version: >=3.0.0,<=3.0.13|>=3.1.0,<3.1.13
Reported by:
FriendsOfPHP/security-advisories -
SS-2016-008: Password encryption salt expiry
Affected version: >=3.1.19,<3.1.20|>=3.2.4,<3.2.5|>=3.3.2,<3.3.3|>=3.4.0,<3.4.1
Reported by:
FriendsOfPHP/security-advisories -
SS-2016-014: Pre-existing alc_enc cookies log users in if remember me is disabled
Affected version: >=3.1.19,<3.1.20|>=3.2.4,<3.2.5|>=3.3.2,<3.3.3|>=3.4.0,<3.4.1
Reported by:
FriendsOfPHP/security-advisories -
SS-2016-015: XSS In OptionsetField and CheckboxSetField
Affected version: >=3.1.19,<3.1.20|>=3.2.4,<3.2.5|>=3.3.2,<3.3.3|>=3.4.0,<3.4.1
Reported by:
FriendsOfPHP/security-advisories -
SS-2016-013: Member.Name is not escaped
Affected version: >=3.1.9,<3.1.20|>=3.2.4,<3.2.5|>=3.3.2,<3.3.3|>=3.4.0,<3.4.1
Reported by:
FriendsOfPHP/security-advisories -
SS-2016-011: ChangePasswordForm does not check Member::canLogIn()
Affected version: >=3.1.19,<3.1.20|>=3.2.4,<3.2.5|>=3.3.2,<3.3.3|>=3.4.0,<3.4.1
Reported by:
FriendsOfPHP/security-advisories -
SS-2016-012: Missing ACL on reports
Affected version: >=3.1.19,<3.1.20|>=3.2.4,<3.2.5|>=3.3.2,<3.3.3|>=3.4.0,<3.4.1
Reported by:
FriendsOfPHP/security-advisories -
SS-2015-010: XSS in Director::force_redirect()
Affected version: >=3.1.0,<3.1.12
Reported by:
FriendsOfPHP/security-advisories -
SS-2015-009: XSS In rewritten hash links
Affected version: >=3.0.0,<=3.0.12|>=3.1.0,<=3.1.11
Reported by:
FriendsOfPHP/security-advisories -
SS-2014-015: IE requests not properly behaving with rewritehashlinks
Affected version: >=3.0.0,<=3.0.12|>=3.1.0,<=3.1.11
Reported by:
FriendsOfPHP/security-advisories -
Reported by:
FriendsOfPHP/security-advisories -
SS-2015-004: TreeDropdownField and TreeMultiSelectField XSS
Affected version: >=3.1.0,<=3.1.9
Reported by:
FriendsOfPHP/security-advisories -
Reported by:
FriendsOfPHP/security-advisories -
Reported by:
FriendsOfPHP/security-advisories