Vulnerabilities > CVE-2021-41559 - XML Entity Expansion vulnerability in Silverstripe
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
NONE Availability impact
HIGH Summary
Silverstripe silverstripe/framework 4.8.1 has a quadratic blowup in Convert::xml2array() that enables a remote attack via a crafted XML document.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
References
- https://github.com/silverstripe/silverstripe-framework/releases
- https://github.com/silverstripe/silverstripe-framework/releases
- https://www.silverstripe.org/download/security-releases/
- https://www.silverstripe.org/download/security-releases/
- https://www.silverstripe.org/download/security-releases/cve-2021-41559
- https://www.silverstripe.org/download/security-releases/cve-2021-41559