VYPR

Bitnami package

silverstripe

pkg:bitnami/silverstripe

Vulnerabilities (13)

  • CVE-2022-37421MedNov 23, 2022
    affected >= 3.0.0, < 4.11.3fixed 4.11.3

    Silverstripe silverstripe/cms through 4.11.0 allows XSS.

  • CVE-2022-28803MedJun 29, 2022
    affected < 4.10.9fixed 4.10.9

    In SilverStripe Framework through 2022-04-07, Stored XSS can occur in javascript link tags added via XMLHttpRequest (XHR).

  • CVE-2022-24444MedJun 28, 2022
    affected < 2.4.0fixed 2.4.0

    Silverstripe silverstripe/framework through 4.10 allows Session Fixation.

  • CVE-2021-41559MedJun 28, 2022
    affected < 4.10.9fixed 4.10.9

    Silverstripe silverstripe/framework 4.8.1 has a quadratic blowup in Convert::xml2array() that enables a remote attack via a crafted XML document.

  • CVE-2021-28661MedOct 7, 2021
    affected >= 3.0.0, < 3.4.1fixed 3.4.1

    Default SilverStripe GraphQL Server (aka silverstripe/graphql) 3.x through 3.4.1 permission checker not inherited by query subclass.

  • CVE-2021-36150MedOct 7, 2021
    affected >= 1.0.0, < 1.8.1fixed 1.8.1

    SilverStripe Framework through 4.8.1 allows XSS.

  • CVE-2020-26136MedJun 8, 2021
    affected < 4.6.0fixed 4.6.0

    In SilverStripe through 4.6.0-rc1, GraphQL doesn't honour MFA (multi-factor authentication) when using basic authentication.

  • CVE-2020-26138MedJun 8, 2021
    affected < 4.6.0fixed 4.6.0

    In SilverStripe through 4.6.0-rc1, a FormField with square brackets in the field name skips validation.

  • CVE-2020-25817MedJun 8, 2021
    affected < 4.6.0fixed 4.6.0

    SilverStripe through 4.6.0-rc1 has an XXE Vulnerability in CSSContentParser. A developer utility meant for parsing HTML within unit tests can be vulnerable to XML External Entity (XXE) attacks. When this developer utility is misused for purposes involving external or user submitt

  • CVE-2020-9311MedJul 15, 2020
    affected >= 3.0.0, < 3.7.5fixed 3.7.5

    In SilverStripe through 4.5, malicious users with a valid Silverstripe CMS login (usually CMS access) can craft profile information which can lead to XSS for other users through specially crafted login form URLs.

  • CVE-2020-6165MedJul 15, 2020
    affected >= 3.2.0, < 3.2.4fixed 3.2.4

    SilverStripe 4.5.0 allows attackers to read certain records that should not have been placed into a result set. This affects silverstripe/recipe-cms. The automatic permission-checking mechanism in the silverstripe/graphql module does not provide complete protection against lists

  • CVE-2020-6164HigJul 15, 2020
    affected < 3.0.0fixed 3.0.0

    In SilverStripe through 4.5.0, a specific URL path configured by default through the silverstripe/framework module can be used to disclose the fact that a domain is hosting a Silverstripe application. There is no disclosure of the specific version. The functionality on this URL p

  • CVE-2020-9280HigApr 15, 2020
    affected >= 4.0.0, < 4.5.0fixed 4.5.0

    In SilverStripe through 4.5, files uploaded via Forms to folders migrated from Silverstripe CMS 3.x may be put to the default "/Uploads" folder instead. This affects installations which allowed upload folder protection via the optional silverstripe/secureassets module under 3.x.