PT-2012-2023 · Silverstripe · Silverstripe

Henri Salo

·

Published

2012-09-17

·

Updated

2022-05-17

·

CVE-2011-4962

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SilverStripe versions 2.4.0 through 2.4.5
Description The issue allows remote attackers to execute arbitrary code via a crafted cookie in a user comment submission, which is not properly handled when it is deserialized. This occurs in the code/sitefeatures/PageCommentInterface.php file.
Recommendations For SilverStripe versions 2.4.0 through 2.4.5, update to version 2.4.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the PageCommentInterface.php file or disabling the comment submission feature until a patch is applied. Avoid using the affected PageCommentInterface.php file in the user comment submission process until the issue is resolved.

Exploit

Fix

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-4962
GHSA-GV6C-59H4-9PMG

Affected Products

Silverstripe