Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v68g-62v9-39w5

Опубликовано: 29 июн. 2022
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Unpublished, protected files can be published via shortcode

Silverstripe silverstripe/assets through 1.10 is vulnerable to improper access control that allows protected images to be published by changing an existing image short code on website content. Draft protected images can be published by changing an existing image shortcode on website content to match the ID of the draft protected image and then publishing the website content.

Пакеты

Наименование

silverstripe/assets

composer
Затронутые версииВерсия исправления

>= 1.0.0, < 1.10.1

1.10.1

EPSS

Процентиль: 56%
0.00332
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 4.3
nvd
больше 3 лет назад

Silverstripe silverstripe/assets through 1.10 is vulnerable to improper access control that allows protected images to be published by changing an existing image short code on website content.

EPSS

Процентиль: 56%
0.00332
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-287