Title |
Severity |
Exploit |
Date |
Affected Version |
silverstripe/framework may disclose database credentials during connection failure
|
Medium
|
|
May 28, 2024
|
>= 3.7.0-rc1 < 3.7.1
>= 4.0.0-rc1 < 4.0.5
>= 4.1.0-rc1 < 4.1.3
>= 4.2.0-rc1 < 4.2.2
|
silverstripe/framework allows upload of dangerous file types
|
High
|
|
May 27, 2024
|
>= 3.6.5-rc1 < 3.6.6
>= 4.0.3-rc1 < 4.0.4
>= 4.1.0-rc1 < 4.1.1
|
silverstripe/framework vulnerable to member disclosure in login form
|
Medium
|
|
May 27, 2024
|
>= 4.0.0-rc1 < 4.0.4
>= 4.1.0-rc1 < 4.1.1
|
silverstripe/framework sends passwords back to browsers under some circumstances
|
Low
|
|
May 27, 2024
|
>= 3.5.5-rc1 < 3.7.0
>= 4.0.3-rc1 < 4.0.4
>= 4.1.0-rc1 < 4.1.1
|
silverstripe/framework uploaded PHP script execution in assets
|
Medium
|
|
May 27, 2024
|
>= 4.0.0-rc1 < 4.0.4
>= 4.1.0-rc1 < 4.1.1
|
silverstripe/framework code execution vulnerability
|
High
|
|
May 27, 2024
|
>= 4.0.3-rc1 < 4.0.4
>= 4.1.0-rc1 < 4.1.1
|
silverstripe/framework BackURL validation bypass with malformed URLs
|
High
|
|
May 27, 2024
|
>= 4.0.0-rc1 < 4.0.4
>= 4.1.0-rc1 < 4.1.1
|
silverstripe/framework's install.php script discloses sensitive data by pre-populating DB credential forms
|
Medium
|
|
May 27, 2024
|
>= 4.0.0-rc1 < 4.0.1
|
silverstripe/framework Privilege Escalation Risk in Member Edit form
|
Medium
|
|
May 27, 2024
|
>= 3.5.7-rc1 < 3.5.8
>= 3.6.0-rc1 < 3.6.6
>= 4.0.0-rc1 < 4.0.4
>= 4.1.0-rc1 < 4.1.1
|
silverstripe/framework's URL parameters `isDev` and `isTest` unguarded
|
Medium
|
|
May 27, 2024
|
>= 4.0.0-rc1 < 4.0.4
>= 4.1.0rc1 < 4.1.1
|