Описание
Silverstripe silverstripe/assets through 1.10 is vulnerable to improper access control that allows protected images to be published by changing an existing image short code on website content.
Ссылки
- Release NotesVendor Advisory
- PatchThird Party Advisory
- ExploitThird Party Advisory
- Release NotesVendor Advisory
- Not ApplicableVendor Advisory
- Release NotesVendor Advisory
- Release NotesVendor Advisory
- PatchThird Party Advisory
- ExploitThird Party Advisory
- Release NotesVendor Advisory
- Not ApplicableVendor Advisory
- Release NotesVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.10.1 (исключая)
cpe:2.3:a:silverstripe:assets:*:*:*:*:*:*:*:*
EPSS
Процентиль: 56%
0.00332
Низкий
4.3 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-287
Связанные уязвимости
CVSS3: 4.3
github
больше 3 лет назад
Unpublished, protected files can be published via shortcode
EPSS
Процентиль: 56%
0.00332
Низкий
4.3 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-287