CVE-2019-5715

All versions of SilverStripe 3 prior to 3.6.7 and 3.7.3, and all versions of SilverStripe 4 prior to 4.0.7, 4.1.5, 4.2.4, and 4.3.1 allows Reflected SQL Injection through Form and DataObject.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
silverstripesilverstripe
3.0.0 ≤
𝑥
< 3.6.7
silverstripesilverstripe
3.7.0 ≤
𝑥
< 3.7.3
silverstripesilverstripe
4.0.0 ≤
𝑥
< 4.0.7
silverstripesilverstripe
4.1.0 ≤
𝑥
< 4.1.5
silverstripesilverstripe
4.2.0 ≤
𝑥
< 4.2.4
silverstripesilverstripe
4.3.0
𝑥
= Vulnerable software versions