Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j8gq-w53g-9p23

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

SilverStripe 2.3.x before 2.3.12 and 2.4.x before 2.4.6 allows remote authenticated users with the EDIT_PERMISSIONS permission to gain administrator privileges via a TreeMultiselectField that includes admin groups when adding a user to the selected groups.

SilverStripe 2.3.x before 2.3.12 and 2.4.x before 2.4.6 allows remote authenticated users with the EDIT_PERMISSIONS permission to gain administrator privileges via a TreeMultiselectField that includes admin groups when adding a user to the selected groups.

EPSS

Процентиль: 65%
0.00495
Низкий

Связанные уязвимости

nvd
больше 13 лет назад

SilverStripe 2.3.x before 2.3.12 and 2.4.x before 2.4.6 allows remote authenticated users with the EDIT_PERMISSIONS permission to gain administrator privileges via a TreeMultiselectField that includes admin groups when adding a user to the selected groups.

debian
больше 13 лет назад

SilverStripe 2.3.x before 2.3.12 and 2.4.x before 2.4.6 allows remote ...

EPSS

Процентиль: 65%
0.00495
Низкий