Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Ingo Schommer

Researcher fromSilverstripe Ltd.
#21133of 53,633
11.8Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2020-20568
7.5
2020-04-15
Silverstripe · Silverstripe · CVE-2020-9280
**Name of the Vulnerable Software and Affected Versions** SilverStripe versions prior to 4.6 **Description** The issue affects files uploaded via Forms to folders migrated from Silverstripe CMS 3.x, where they may be put in the default "/Uploads" folder instead of the intended location. This impacts installations that had upload folder protection enabled via the silverstripe/secureassets module under 3.x, which is installed and enabled by default on the Common Web Platform (CWP). The issue only affects files uploaded after an upgrade to 4.x. **Recommendations** For SilverStripe versions prior to 4.6, update to version 4.6 or later to resolve the issue.
PT-2012-1338
4.3
2012-08-26
Silverstripe · Silverstripe · CVE-2010-5095
**Name of the Vulnerable Software and Affected Versions** SilverStripe versions 2.3.x through 2.3.5 **Description** A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML via vectors related to DataObjectSet pagination. **Recommendations** For versions 2.3.x through 2.3.5, update to version 2.3.6 or later to resolve the issue.