PT-2024-40009 · Silverstripe · Silverstripe/Postgresql+1

Published

2024-05-28

·

Updated

2024-05-28

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions silverstripe/framework (affected versions not specified)
Description A potential SQL injection issue was identified when using the silverstripe/postgresql database adapter. Although it is unlikely to be exploitable, the issue has been patched to ensure table names are safely escaped before being passed to database adapters or user code.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Weakness Enumeration

Related Identifiers

GHSA-265Q-222X-52M6

Affected Products

Silverstripe/Framework
Silverstripe/Postgresql