CVE-2023-22728

CVSS V2 None CVSS V3 None
Description
Silverstripe Framework is the Model-View-Controller framework that powers the Silverstripe content management system. Prior to version 4.12.15, the GridField print view incorrectly validates the permission of DataObjects potentially allowing a content author to view records they are not authorised to access. Users should upgrade to Silverstripe Framework 4.12.15 or above to address the issue.
Overview
  • CVE ID
  • CVE-2023-22728
  • Assigner
  • security-advisories@github.com
  • Vulnerability Status
  • Received
  • Published Version
  • 2023-04-26T14:15:09
  • Last Modified Date
  • 2023-04-26T14:15:09
History
Created Old Value New Value Data Type Notes
2023-04-26 15:01:19 Added to TrackCVE
2023-04-26 15:01:23 Weakness Enumeration new