PT-2020-20568 · Silverstripe · Silverstripe

Ingo Schommer

·

Published

2020-04-15

·

Updated

2024-03-06

·

CVE-2020-9280

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SilverStripe versions prior to 4.6
Description The issue affects files uploaded via Forms to folders migrated from Silverstripe CMS 3.x, where they may be put in the default "/Uploads" folder instead of the intended location. This impacts installations that had upload folder protection enabled via the silverstripe/secureassets module under 3.x, which is installed and enabled by default on the Common Web Platform (CWP). The issue only affects files uploaded after an upgrade to 4.x.
Recommendations For SilverStripe versions prior to 4.6, update to version 4.6 or later to resolve the issue.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-SILVERSTRIPE-2020-9280
CVE-2020-9280
GHSA-592M-4533-RXQ9

Affected Products

Silverstripe