GHSA-g8wr-r2v2-vqc6: Input Validation
Impact The userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server.
Reported by Jack Wallace from Bastion Security
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/silverstripe/userformsto a version that resolves this vulnerability.Fixed in 7.1.1 - Upgrade
Upgrade
composer/silverstripe/userformsto a version that resolves this vulnerability.Fixed in 7.0.7 - Upgrade
Upgrade
composer/silverstripe/userformsto a version that resolves this vulnerability.Fixed in 6.4.9
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The CVSS vector indicates an attacker needs low-level privileges and network access. No user interaction is required.
How difficult is exploitation likely to be?
The attack complexity is rated low, meaning exploitation does not depend on special conditions beyond the required low-level privileges.
What could a successful exploit affect?
A successful exploit can result in arbitrary code execution on the server. The vulnerability is rated as having high impact on confidentiality, integrity, and availability.