GHSA-592m-4533-rxq9

    Dashboard / Vulnerabilities / GHSA-592m-4533-rxq9

    GHSA-592m-4533-rxq9

    Published: 24 May 2022Last Modified: 25 Apr 2024

    Summary: SilverStripe Folders migrated from 3.x may be unsafe to upload to

    Details: In SilverStripe through 4.5, files uploaded via Forms to folders migrated from Silverstripe CMS 3.x may be put to the default "/Uploads" folder instead. This affects installations which allowed upload folder protection via the optional silverstripe/secureassets module under 3.x. This module is installed and enabled by default on the Common Web Platform (CWP). The vulnerability only affects files uploaded after an upgrade to 4.x.

    Affected packages

    Package

    Name: silverstripe/framework

    Purl: pkg:composer/silverstripe/framework

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 4.0.0
    Fixed -4.4.6

    Affected versions

    4.0.0
    4.0.1
    4.0.1-rc1
    4.0.2
    4.0.3
    4.0.4
    4.0.5
    4.0.6
    4.0.7

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-592m-4533-rxq9 | CVE-DB