PT-2022-11429 · Silverstripe · Silverstripe/Framework

Matthew Dekker

·

Published

2022-06-28

·

Updated

2024-03-06

·

CVE-2021-41559

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Silverstripe silverstripe/framework versions 4.8.1 through 4.10.9
Description The issue is related to a quadratic blowup in the Convert::xml2array() function, which can be exploited via a crafted XML document to enable a remote attack.
Recommendations For versions 4.8.1 through 4.10.9, consider disabling the Convert::xml2array() function until a patch is available to prevent potential exploitation. Restrict access to crafted XML documents to minimize the risk of a remote attack.

Exploit

Fix

XML Entity Expansion

Weakness Enumeration

Related Identifiers

BIT-SILVERSTRIPE-2021-41559
CVE-2021-41559
GHSA-9FMG-89FX-R33W

Affected Products

Silverstripe/Framework