Vulnerabilities > Silverstripe > Silverstripe > 2.3.11

DATE CVE VULNERABILITY TITLE RISK
2016-04-13 CVE-2015-8606 Cross-site Scripting vulnerability in Silverstripe
Multiple cross-site scripting (XSS) vulnerabilities in SilverStripe CMS & Framework before 3.1.16 and 3.2.x before 3.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) Locale or (2) FailedLoginCount parameter to admin/security/EditForm/field/Members/item/new/ItemEditForm.
4.3
2014-04-08 CVE-2011-4958 Cross-Site Scripting vulnerability in Silverstripe
Cross-site scripting (XSS) vulnerability in the process function in SSViewer.php in SilverStripe before 2.3.13 and 2.4.x before 2.4.6 allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING to template placeholders, as demonstrated by a request to (1) admin/reports/, (2) admin/comments/, (3) admin/, (4) admin/show/, (5) admin/assets/, and (6) admin/security/.
4.3
2012-09-17 CVE-2012-4968 Cross-Site Scripting vulnerability in Silverstripe
Multiple cross-site scripting (XSS) vulnerabilities in SilverStripe 2.3.x before 2.3.13 and 2.4.x before 2.4.7 allow remote attackers to inject arbitrary web script or HTML via (1) a crafted string to the AbsoluteLinks, (2) BigSummary, (3) ContextSummary, (4) EscapeXML, (5) FirstParagraph, (6) FirstSentence, (7) Initial, (8) LimitCharacters, (9) LimitSentences, (10) LimitWordCount, (11) LimitWordCountXML, (12) Lower, (13) LowerCase, (14) NoHTML, (15) Summary, (16) Upper, (17) UpperCase, or (18) URL method in a template, different vectors than CVE-2012-0976.
4.3
2012-09-17 CVE-2011-4961 Permissions, Privileges, and Access Controls vulnerability in Silverstripe
SilverStripe 2.3.x before 2.3.12 and 2.4.x before 2.4.6 allows remote authenticated users with the EDIT_PERMISSIONS permission to gain administrator privileges via a TreeMultiselectField that includes admin groups when adding a user to the selected groups.
6.0
2012-09-17 CVE-2011-4960 SQL Injection vulnerability in Silverstripe
SQL injection vulnerability in the Folder::findOrMake method in SilverStripe 2.3.x before 2.3.12 and 2.4.x before 2.4.6 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
network
low complexity
silverstripe CWE-89
7.5
2012-09-17 CVE-2011-4959 SQL Injection vulnerability in Silverstripe
SQL injection vulnerability in the addslashes method in SilverStripe 2.3.x before 2.3.12 and 2.4.x before 2.4.6, when connected to a MySQL database using far east character encodings, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
6.8
2012-08-26 CVE-2010-5090 Permissions, Privileges, and Access Controls vulnerability in Silverstripe
SilverStripe before 2.4.2 allows remote authenticated users to change administrator passwords via vectors related to admin/security.
network
low complexity
silverstripe CWE-264
4.0
2012-08-26 CVE-2010-5089 Permissions, Privileges, and Access Controls vulnerability in Silverstripe
SilverStripe before 2.4.2 does not properly restrict access to pages in draft mode, which allows remote attackers to obtain sensitive information.
4.3