Описание
silverstripe/framework SQL injection in full text search
When performing a fulltext search in SilverStripe 4.0.0 the 'start' querystring parameter is never escaped safely. This exposes a possible SQL injection vulnerability.
The issue exists in 3.5 and 3.6 but is less vulnerable, as SearchForm sanitises these variables prior to passing to mysql.
Ссылки
- https://github.com/silverstripe/silverstripe-framework/commit/099a5a3c2d99ed39bdd8815e1e2790bb9351770b
- https://github.com/silverstripe/silverstripe-framework/commit/a8465900bdc77199176c953890ce7587045b1ea4
- https://github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/framework/SS-2017-008-1.yaml
- https://www.silverstripe.org/download/security-releases/ss-2017-008
Пакеты
Наименование
silverstripe/framework
composer
Затронутые версииВерсия исправления
>= 3.5.0-rc1, < 3.5.6
3.5.6
Наименование
silverstripe/framework
composer
Затронутые версииВерсия исправления
>= 3.6.0-rc1, < 3.6.3
3.6.3
Наименование
silverstripe/framework
composer
Затронутые версииВерсия исправления
>= 4.0.0-rc1, < 4.0.1
4.0.1
8.8 High
CVSS3
Дефекты
CWE-89
8.8 High
CVSS3
Дефекты
CWE-89