Skip to main content

Vendor archive

silverstripe CVEs

Beta · best-effort

89 CVEs tagged to vendor silverstripe4 Critical, 11 High, 70 Medium, 4 Low, 0 Unrated.

CVE-2010-5094

Published Aug 26, 2012

The deleteinstallfiles function in control/ContentController.php in SilverStripe 2.3.x before 2.3.7 does not require ADMIN permissions, which allows remote attackers to delete ind…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5093

Published Aug 26, 2012

Member_ProfileForm in security/Member.php in SilverStripe 2.3.x before 2.3.7 allows remote attackers to hijack user accounts by saving data using the email address (ID) of another…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5092

Published Aug 26, 2012

The Add Member dialog in the Security admin page in SilverStripe 2.4.0 saves user passwords in plaintext, which allows local users to obtain sensitive information by reading a dat…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-5091

Published Aug 26, 2012

The setName function in filesystem/File.php in SilverStripe 2.3.x before 2.3.8 and 2.4.x before 2.4.1 allows remote authenticated users with CMS author privileges to execute arbit…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5090

Published Aug 26, 2012

SilverStripe before 2.4.2 allows remote authenticated users to change administrator passwords via vectors related to admin/security.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5089

Published Aug 26, 2012

SilverStripe before 2.4.2 does not properly restrict access to pages in draft mode, which allows remote attackers to obtain sensitive information.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5088

Published Aug 26, 2012

Multiple cross-site request forgery (CSRF) vulnerabilities in SilverStripe 2.3.x before 2.3.9 and 2.4.x before 2.4.3 allow remote attackers to hijack the authentication of adminis…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5087

Published Aug 26, 2012

SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism and hijack the authentication…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5080

Published Aug 26, 2012

The Security/changepassword URL action in SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 passes a token as a GET parameter while changing a password through email, which…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0976

Published Feb 2, 2012

Cross-site scripting (XSS) vulnerability in admin/EditForm in SilverStripe 2.4.6 allows remote authenticated users with Content Authors privileges to inject arbitrary web script o…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-1593

Published Apr 28, 2010

Multiple cross-site scripting (XSS) vulnerabilities in SilverStripe before 2.3.5 allow remote attackers to inject arbitrary web script or HTML via (1) the CommenterURL parameter t…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6753

Published Apr 27, 2009

SQL injection vulnerability in SilverStripe before 2.2.2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors related to AjaxUniqueTextField.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-1433

Published Apr 24, 2009

SQL injection vulnerability in File::find (filesystem/File.php) in SilverStripe before 2.3.1 allows remote attackers to execute arbitrary SQL commands via the filename parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-2321

Published Apr 27, 2007

Unspecified vulnerability in the search functionality in SilverStripe 2.0.0 has unknown impact and attack vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 76-89 of 89 CVEsPage 4 of 4