Silverstripe Framework is the Model-View-Controller framework that powers the Silverstripe content management system. Prior to version 4.12.15, the GridField print view incorrectly validates the permission of DataObjects potentially allowing a content author to view records they are not authorised to access. Users should upgrade to Silverstripe Framework 4.12.15 or above to address the issue.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-1340 | Silverstripe Framework is the Model-View-Controller framework that powers the Silverstripe content management system. Prior to version 4.12.15, the GridField print view incorrectly validates the permission of DataObjects potentially allowing a content author to view records they are not authorised to access. Users should upgrade to Silverstripe Framework 4.12.15 or above to address the issue. |
Github GHSA |
GHSA-jh3w-6jp2-vqqm | Missing permission check of canView in GridFieldPrintButton |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 31 Jan 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-01-31T16:10:56.483Z
Reserved: 2023-01-06T14:21:05.890Z
Link: CVE-2023-22728
Updated: 2024-08-02T10:13:50.222Z
Status : Modified
Published: 2023-04-26T14:15:09.490
Modified: 2024-11-21T07:45:18.400
Link: CVE-2023-22728
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA