Silverstripe Admin vulnerabilities
4 known vulnerabilities affecting silverstripe/admin.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM4
Vulnerabilities
Page 1 of 1
CVE-2023-49783MEDIUMCVSS 4.3≥ 1.0.0, < 1.13.19≥ 2.0.0, < 2.1.82024-01-23
CVE-2023-49783 [MEDIUM] CWE-863 CVE-2023-49783: Silverstripe Admin provides a basic management interface for the Silverstripe Framework. In versions
Silverstripe Admin provides a basic management interface for the Silverstripe Framework. In versions on the 1.x branch prior to 1.13.19 and on the 2.x branch prior to 2.1.8, users who don't have edit or delete permissions for records exposed in a `ModelAdmin` can still edit or delete records using the CSV import form, provided they have create permi
ghsanvdosv
CVE-2022-38146MEDIUM≥ 1.0.0, < 1.11.32022-11-21
CVE-2022-38146 [MEDIUM] CWE-79 URL XSS vulnerability due to outdated jquery in CMS
URL XSS vulnerability due to outdated jquery in CMS
Silverstripe silverstripe/framework through 4.11 allows XSS (issue 2 of 3).
ghsaosv
CVE-2019-12205MEDIUM≥ 0, < 1.3.52022-05-24
CVE-2019-12205 [MEDIUM] CWE-79 Silverstripe Flash Clipboard Reflected XSS
Silverstripe Flash Clipboard Reflected XSS
SilverStripe versions 3.0.0 until 4.3.5 and 4.4.4 are vulnerable to Flash Clipboard Reflected XSS. Versions 4.3.5 and 4.4.4 of `silverstripe/framework` and version 1.3.5 of `silverstripe/admin` contain a fix for this issue.
ghsaosv
CVE-2021-36150MEDIUM≥ 1.0.0, < 1.8.12021-10-12
CVE-2021-36150 [MEDIUM] CWE-79 Cross-site Scripting in SilverStripe Framework
Cross-site Scripting in SilverStripe Framework
SilverStripe Framework through 4.8.1 allows XSS.
ghsaosv