Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2011-4961

Опубликовано: 17 сент. 2012
Источник: debian
EPSS Низкий

Описание

SilverStripe 2.3.x before 2.3.12 and 2.4.x before 2.4.6 allows remote authenticated users with the EDIT_PERMISSIONS permission to gain administrator privileges via a TreeMultiselectField that includes admin groups when adding a user to the selected groups.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
silverstripeitppackage

Примечания

  • http://seclists.org/oss-sec/2012/q2/209

EPSS

Процентиль: 65%
0.00495
Низкий

Связанные уязвимости

nvd
больше 13 лет назад

SilverStripe 2.3.x before 2.3.12 and 2.4.x before 2.4.6 allows remote authenticated users with the EDIT_PERMISSIONS permission to gain administrator privileges via a TreeMultiselectField that includes admin groups when adding a user to the selected groups.

github
больше 3 лет назад

SilverStripe 2.3.x before 2.3.12 and 2.4.x before 2.4.6 allows remote authenticated users with the EDIT_PERMISSIONS permission to gain administrator privileges via a TreeMultiselectField that includes admin groups when adding a user to the selected groups.

EPSS

Процентиль: 65%
0.00495
Низкий