Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-592m-4533-rxq9

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

SilverStripe Folders migrated from 3.x may be unsafe to upload to

In SilverStripe through 4.5, files uploaded via Forms to folders migrated from Silverstripe CMS 3.x may be put to the default "/Uploads" folder instead. This affects installations which allowed upload folder protection via the optional silverstripe/secureassets module under 3.x. This module is installed and enabled by default on the Common Web Platform (CWP). The vulnerability only affects files uploaded after an upgrade to 4.x.

Пакеты

Наименование

silverstripe/framework

composer
Затронутые версииВерсия исправления

>= 4.0.0, < 4.4.6

4.4.6

Наименование

silverstripe/userforms

composer
Затронутые версииВерсия исправления

>= 5.0.0, < 5.4.2

5.4.2

Наименование

silverstripe/assets

composer
Затронутые версииВерсия исправления

>= 1.0.0, < 1.4.7

1.4.7

Наименование

silverstripe/assets

composer
Затронутые версииВерсия исправления

>= 1.5.0, < 1.5.2

1.5.2

EPSS

Процентиль: 59%
0.00386
Низкий

7.5 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 7.5
nvd
почти 6 лет назад

In SilverStripe through 4.5, files uploaded via Forms to folders migrated from Silverstripe CMS 3.x may be put to the default "/Uploads" folder instead. This affects installations which allowed upload folder protection via the optional silverstripe/secureassets module under 3.x. This module is installed and enabled by default on the Common Web Platform (CWP). The vulnerability only affects files uploaded after an upgrade to 4.x.

EPSS

Процентиль: 59%
0.00386
Низкий

7.5 High

CVSS3

Дефекты

CWE-434