GHSA-39mm-rwm3-29jp: Input Validation
Impact The advanced workflow email template field is vulnerable to a specially crafted payload that can be used to run arbitrary code on the server.
Reported by Steve Boyd Silverstripe Ltd.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/symbiote/silverstripe-advancedworkflowto a version that resolves this vulnerability.Fixed in 7.2.1 - Upgrade
Upgrade
composer/symbiote/silverstripe-advancedworkflowto a version that resolves this vulnerability.Fixed in 7.1.3 - Upgrade
Upgrade
composer/symbiote/silverstripe-advancedworkflowto a version that resolves this vulnerability.Fixed in 6.4.5
Event History
Frequently Asked Questions
What level of access does an attacker need?
The CVSS vector indicates high privileges are required. Exploitation is network-accessible and does not require user interaction.
Which environments are most exposed?
Deployments are at risk when a highly privileged user can access and modify the advanced workflow email template field. The provided data does not identify affected or fixed versions, configuration prerequisites, or temporary mitigations.