Описание
silverstripe/taxonomy SQL Injection vulnerability
There is a vulnerability in silverstripe/taxonomy module that allows SQL injection. This affected controller (TaxonomyDirectoryController) is disabled by default and must be enabled by a developer for the exploit to be possible.
Ссылки
- https://github.com/silverstripe/silverstripe-taxonomy/commit/01a5d9e04b993df507058aa53e6e18efc5ca405b
- https://github.com/silverstripe/silverstripe-taxonomy/commit/d037941e931490c33af5029c676447ed38896ee8
- https://github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/taxonomy/SS-2018-011-1.yaml
- https://www.silverstripe.org/download/security-releases/ss-2018-011
Пакеты
Наименование
silverstripe/taxonomy
composer
Затронутые версииВерсия исправления
>= 1.3.0, < 1.3.1
1.3.1
Наименование
silverstripe/taxonomy
composer
Затронутые версииВерсия исправления
>= 2.0.0, < 2.0.1
2.0.1
7.5 High
CVSS3
Дефекты
CWE-89
7.5 High
CVSS3
Дефекты
CWE-89