Blind SQL Injection via GridFieldSortableHeader
High severity
GitHub Reviewed
Published
Nov 22, 2022
to the GitHub Advisory Database
•
Updated Jan 24, 2024
Package
Affected versions
>= 4.0.0, < 4.10.11
>= 4.11.0, < 4.11.14
Patched versions
4.10.11
4.11.14
Description
Published by the National Vulnerability Database
Nov 21, 2022
Published to the GitHub Advisory Database
Nov 22, 2022
Reviewed
Nov 22, 2022
Last updated
Jan 24, 2024
Gridfield state is vulnerable to SQL injections. The vast majority of Gridfields in Silverstripe CMS are affected by this vulnerability.
An attacker with CMS access could execute an arbitrary SQL statement by adding an SQL payload in some parts of the GridField state.
References