silverstripe/taxonomy SQL Injection vulnerability
High severity
GitHub Reviewed
Published
May 28, 2024
to the GitHub Advisory Database
•
Updated May 28, 2024
Package
Affected versions
>= 1.3.0, < 1.3.1
>= 2.0.0, < 2.0.1
Patched versions
1.3.1
2.0.1
Description
Published to the GitHub Advisory Database
May 28, 2024
Reviewed
May 28, 2024
Last updated
May 28, 2024
There is a vulnerability in silverstripe/taxonomy module that allows SQL injection. This affected controller (
TaxonomyDirectoryController
) is disabled by default and must be enabled by a developer for the exploit to be possible.References