📦

silverstripe

Vendor: silverstripe

Actively Exploited 0 CISA KEV List
PoC / Exploits 2 Code Available
Total RCEs 4 Remote Access
Total CVEs 369 Total Indexed
Avg. EPSS 0.65% Exploit Prob.
Latest CVE CVE-2022-37421 Nov 23

Security Vulnerability Index

Page 3 / 37
2.7 CVSS

In SilverStripe through 4.3.3, there is access escalation for CMS users with limited access through permission cache pollution.

EPSS: 0.30%
5.3 CVSS

SilverStripe through 4.3.3 has incorrect access control for protected files uploaded via Upload::loadIntoFile(). An attacker may be able to guess a filename in silverstripe/assets via the AssetControlExtension.

EPSS: 0.26%
6.1 CVSS

SilverStripe through 4.3.3 has Flash Clipboard Reflected XSS.

EPSS: 0.38%
9.8 CVSS

In SilverStripe through 4.3.3, a missing warning about leaving install.php in a public webroot can lead to unauthenticated admin access.

EPSS: 0.83%
6.3 CVSS

SilverStripe through 4.3.3 allows session fixation in the "change password" form.

EPSS: 0.05%
9.8 CVSS

All versions of SilverStripe 3 prior to 3.6.7 and 3.7.3, and all versions of SilverStripe 4 prior to 4.0.7, 4.1.5, 4.2.4, and 4.3.1 allows Reflected SQL Injection through Form and DataObject.

EPSS: 0.32%
5.5 CVSS

In the CSV export feature of SilverStripe before 3.5.6, 3.6.x before 3.6.3, and 4.x before 4.0.1, it's possible for the output to contain macros and scripts, which may be executed if imported without sanitization into common software (including Microsoft Excel). For example, the CSV data may contain untrusted user input from the "First Name" field of a user's /myprofile page.

EPSS: 0.21%
5.3 CVSS

Response discrepancy in the login and password reset forms in SilverStripe CMS before 3.5.5 and 3.6.x before 3.6.1 allows remote attackers to enumerate users via timing attacks.

EPSS: 0.39%
6.1 CVSS

SilverStripe CMS before 3.6.1 has XSS via an SVG document that is mishandled by (1) the Insert Media option in the content editor or (2) an admin/assets/add pathname, as demonstrated by the admin/pages/edit/EditorToolbar/MediaForm/field/AssetUploadField/upload URI, aka issue SS-2017-017.

EPSS: 0.37%
6.1 CVSS

There is XSS in SilverStripe CMS before 3.4.4 and 3.5.x before 3.5.2. The attack vector is a page name. An example payload is a crafted JavaScript event handler within a malformed SVG element.

EPSS: 0.26%