Show filters
96 Total Results
Displaying 11-20 of 96
Sort by:
Attacker Value
Unknown

CVE-2023-22728

Disclosure Date: April 26, 2023 (last updated October 08, 2023)
Silverstripe Framework is the Model-View-Controller framework that powers the Silverstripe content management system. Prior to version 4.12.15, the GridField print view incorrectly validates the permission of DataObjects potentially allowing a content author to view records they are not authorised to access. Users should upgrade to Silverstripe Framework 4.12.15 or above to address the issue.
Attacker Value
Unknown

CVE-2023-28104

Disclosure Date: March 16, 2023 (last updated October 08, 2023)
`silverstripe/graphql` serves Silverstripe data as GraphQL representations. In versions 4.2.2 and 4.1.1, an attacker could use a specially crafted graphql query to execute a denial of service attack against a website which has a publicly exposed graphql endpoint. This mostly affects websites with particularly large/complex graphql schemas. Users should upgrade to `silverstripe/graphql` 4.2.3 or 4.1.2 to remedy the vulnerability.
Attacker Value
Unknown

CVE-2023-23315

Disclosure Date: March 01, 2023 (last updated October 08, 2023)
The PrestaShop e-commerce platform module stripejs contains a Blind SQL injection vulnerability up to version 4.5.5. The method `stripejsValidationModuleFrontController::initContent()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.
Attacker Value
Unknown

CVE-2022-42949

Disclosure Date: December 21, 2022 (last updated October 08, 2023)
Silverstripe silverstripe/subsites through 2.6.0 has Insecure Permissions.
Attacker Value
Unknown

CVE-2022-38147

Disclosure Date: November 23, 2022 (last updated October 08, 2023)
Silverstripe silverstripe/framework through 4.11 allows XSS (issue 3 of 3).
Attacker Value
Unknown

CVE-2022-37421

Disclosure Date: November 23, 2022 (last updated October 08, 2023)
Silverstripe silverstripe/cms through 4.11.0 allows XSS.
Attacker Value
Unknown

CVE-2022-37430

Disclosure Date: November 23, 2022 (last updated October 08, 2023)
Silverstripe silverstripe/framework through 4.11 allows XSS vulnerability via href attribute of a link (issue 2 of 2).
Attacker Value
Unknown

CVE-2022-37429

Disclosure Date: November 23, 2022 (last updated October 08, 2023)
Silverstripe silverstripe/framework through 4.11 allows XSS (issue 1 of 2) via JavaScript payload to the href attribute of a link by splitting a javascript URL with white space characters.
Attacker Value
Unknown

CVE-2022-38145

Disclosure Date: November 23, 2022 (last updated October 08, 2023)
Silverstripe silverstripe/framework through 4.11 allows XSS (issue 1 of 3) via remote attackers adding a Javascript payload to a page's meta description and get it executed in the versioned history compare view.
Attacker Value
Unknown

CVE-2022-38724

Disclosure Date: November 23, 2022 (last updated October 08, 2023)
Silverstripe silverstripe/framework through 4.11.0, silverstripe/assets through 1.11.0, and silverstripe/asset-admin through 1.11.0 allow XSS.