296,147
Total vulnerabilities in the database
SilverStripe through 4.3.3 has incorrect access control for protected files uploaded via Upload::loadIntoFile(). An attacker may be able to guess a filename in silverstripe/assets via the AssetControlExtension.
Software | From | Fixed in |
---|---|---|
silverstripe / silverstripe | - | 4.3.3.x |
![]() |
- | 3.6.8 |
![]() |
3.7.0 | 3.7.4 |
![]() |
4.0.0 | 4.3.6 |
![]() |
4.4.0 | 4.4.4 |