Show filters
96 Total Results
Displaying 21-30 of 96
Sort by:
Attacker Value
Unknown
CVE-2022-38462
Disclosure Date: November 22, 2022 (last updated December 22, 2024)
Silverstripe silverstripe/framework through 4.11 is vulnerable to XSS by carefully crafting a return URL on a /dev/build or /Security/login request.
0
Attacker Value
Unknown
CVE-2022-38146
Disclosure Date: November 21, 2022 (last updated December 22, 2024)
Silverstripe silverstripe/framework through 4.11 allows XSS (issue 2 of 3).
0
Attacker Value
Unknown
CVE-2022-38148
Disclosure Date: November 21, 2022 (last updated December 22, 2024)
Silverstripe silverstripe/framework through 4.11 allows SQL Injection.
0
Attacker Value
Unknown
CVE-2022-28803
Disclosure Date: June 29, 2022 (last updated February 24, 2025)
In SilverStripe Framework through 2022-04-07, Stored XSS can occur in javascript link tags added via XMLHttpRequest (XHR).
0
Attacker Value
Unknown
CVE-2022-29858
Disclosure Date: June 28, 2022 (last updated February 24, 2025)
Silverstripe silverstripe/assets through 1.10 is vulnerable to improper access control that allows protected images to be published by changing an existing image short code on website content.
0
Attacker Value
Unknown
CVE-2022-25238
Disclosure Date: June 28, 2022 (last updated February 24, 2025)
Silverstripe silverstripe/framework through 4.10.0 allows XSS, inside of script tags that can can be added to website content via XHR by an authenticated CMS user if the cwp-core module is not installed on the sanitise_server_side contig is not set to true in project code.
0
Attacker Value
Unknown
CVE-2022-24444
Disclosure Date: June 28, 2022 (last updated February 24, 2025)
Silverstripe silverstripe/framework through 4.10 allows Session Fixation.
0
Attacker Value
Unknown
CVE-2021-41559
Disclosure Date: June 28, 2022 (last updated February 24, 2025)
Silverstripe silverstripe/framework 4.8.1 has a quadratic blowup in Convert::xml2array() that enables a remote attack via a crafted XML document.
0
Attacker Value
Unknown
CVE-2022-29254
Disclosure Date: June 09, 2022 (last updated February 23, 2025)
silverstripe-omnipay is a SilverStripe integration with Omnipay PHP payments library. For a subset of Omnipay gateways (those that use intermediary states like `isNotification()` or `isRedirect()`), if the payment identifier or success URL is exposed it is possible for payments to be prematurely marked as completed without payment being taken. This is mitigated by the fact that most payment gateways hide this information from users, however some issuing banks offer flawed 3DSecure implementations that may inadvertently expose this data. The following versions have been patched to fix this issue: `2.5.2`, `3.0.2`, `3.1.4`, and `3.2.1`. There are no known workarounds for this vulnerability.
0
Attacker Value
Unknown
CVE-2022-29188
Disclosure Date: May 21, 2022 (last updated February 23, 2025)
Smokescreen is an HTTP proxy. The primary use case for Smokescreen is to prevent server-side request forgery (SSRF) attacks in which external attackers leverage the behavior of applications to connect to or scan internal infrastructure. Smokescreen also offers an option to deny access to additional (e.g., external) URLs by way of a deny list. There was an issue in Smokescreen that made it possible to bypass the deny list feature by surrounding the hostname with square brackets (e.g. `[example.com]`). This only impacted the HTTP proxy functionality of Smokescreen. HTTPS requests were not impacted. Smokescreen version 0.0.4 contains a patch for this issue.
0