PT-2012-2023 · Silverstripe · Silverstripe
Henri Salo
·
Published
2012-09-17
·
Updated
2022-05-17
·
CVE-2011-4962
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
SilverStripe versions 2.4.0 through 2.4.5
Description
The issue allows remote attackers to execute arbitrary code via a crafted cookie in a user comment submission, which is not properly handled when it is deserialized. This occurs in the
code/sitefeatures/PageCommentInterface.php file.Recommendations
For SilverStripe versions 2.4.0 through 2.4.5, update to version 2.4.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the
PageCommentInterface.php file or disabling the comment submission feature until a patch is applied. Avoid using the affected PageCommentInterface.php file in the user comment submission process until the issue is resolved.Exploit
Fix
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Silverstripe