CVE-2011-4961

EUVD-2011-4868
SilverStripe 2.3.x before 2.3.12 and 2.4.x before 2.4.6 allows remote authenticated users with the EDIT_PERMISSIONS permission to gain administrator privileges via a TreeMultiselectField that includes admin groups when adding a user to the selected groups.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 65%
Affected Products (NVD)
VendorProductVersion
silverstripesilverstripe
2.3.0
silverstripesilverstripe
2.3.1
silverstripesilverstripe
2.3.2
silverstripesilverstripe
2.3.3
silverstripesilverstripe
2.3.4
silverstripesilverstripe
2.3.5
silverstripesilverstripe
2.3.6
silverstripesilverstripe
2.3.7
silverstripesilverstripe
2.3.8
silverstripesilverstripe
2.3.9
silverstripesilverstripe
2.3.10
silverstripesilverstripe
2.3.11
silverstripesilverstripe
2.4.0
silverstripesilverstripe
2.4.1
silverstripesilverstripe
2.4.2
silverstripesilverstripe
2.4.3
silverstripesilverstripe
2.4.4
silverstripesilverstripe
2.4.5
𝑥
= Vulnerable software versions
Common Weakness Enumeration