Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Silverstripe Framework has missing permission check of canView in GridFieldPrintButton
Vulnerability Description
Silverstripe Framework is the Model-View-Controller framework that powers the Silverstripe content management system. Prior to version 4.12.15, the GridField print view incorrectly validates the permission of DataObjects potentially allowing a content author to view records they are not authorised to access. Users should upgrade to Silverstripe Framework 4.12.15 or above to address the issue.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
授权机制缺失
Vulnerability Title
silverstripe framework 安全漏洞
Vulnerability Description
silverstripe framework是一套CMS网站框架。 Silverstripe Framework 4.12.5版本及之前版本存在安全漏洞,该漏洞源于GridField 打印视图错误地验证了 DataObjects 的权限。攻击者利用该漏洞可以查看他们无权访问的记录。
CVSS Information
N/A
Vulnerability Type
N/A