Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vgxh-x8jv-hmff

Опубликовано: 27 мая 2024
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

silverstripe/framework code execution vulnerability

There is a vulnerability whereby arbitrary global functions may be executed if malicious user input is passed through to in the second argument of ViewableData::renderWith. This argument resolves associative arrays as template placeholders. This exploit requires that user code has been written which makes use of the second argument in renderWith and where user input is passed directly as a value in an associative array without sanitisation such as Convert::raw2xml().

ViewableData::customise is not vulnerable.

Пакеты

Наименование

silverstripe/framework

composer
Затронутые версииВерсия исправления

>= 4.0.3-rc1, < 4.0.4

4.0.4

Наименование

silverstripe/framework

composer
Затронутые версииВерсия исправления

>= 4.1.0-rc1, < 4.1.1

4.1.1

7.5 High

CVSS3

Дефекты

CWE-74

7.5 High

CVSS3

Дефекты

CWE-74