First published: Sun Nov 21 2021(Updated: )
CVE-2022-38148 - Blind SQL Injection via GridFieldSortableHeader
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/silverstripe/framework | >=4.0.0<4.10.11>=4.11.0<4.11.14 | |
Silverstripe Framework | <=4.11.0 | |
composer/silverstripe/framework | >=4.11.0<4.11.14 | 4.11.14 |
composer/silverstripe/framework | >=4.0.0<4.10.11 | 4.10.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-38148 is a vulnerability that allows SQL Injection in Silverstripe framework versions 4.0.0 to 4.10.11 and 4.11.0 to 4.11.14.
The severity of CVE-2022-38148 is high, with a CVSS score of 8.8.
CVE-2022-38148 allows for SQL Injection in Silverstripe framework through version 4.11.
To fix CVE-2022-38148, update Silverstripe framework to a version higher than 4.11.14 or apply the necessary security patches.
More information about CVE-2022-38148 can be found at the following links: [Silverstripe Security Releases](https://www.silverstripe.org/download/security-releases/cve-2022-38148), [Silverstripe Forum Releases](https://forum.silverstripe.org/c/releases), [Silverstripe Blog](https://www.silverstripe.org/blog/tag/release).