Lucene search

K
cve[email protected]CVE-2023-48714
HistoryJan 23, 2024 - 2:15 p.m.

CVE-2023-48714

2024-01-2314:15:37
CWE-732
CWE-200
web.nvd.nist.gov
16
cve-2023-48714
silverstripe framework
unauthorized access
record titles
gridfieldaddexistingautocompleter
security vulnerability

4.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

4.3 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

14.2%

Silverstripe Framework is the framework that forms the base of the Silverstripe content management system. Prior to versions 4.13.39 and 5.1.11, if a user should not be able to see a record, but that record can be added to a GridField using the GridFieldAddExistingAutocompleter component, the record’s title can be accessed by that user. Versions 4.13.39 and 5.1.11 contain a fix for this issue.

Affected configurations

Vulners
NVD
Node
silverstripeframeworkRange<4.13.39
OR
silverstripeframeworkRange5.0.05.1.11
VendorProductVersionCPE
silverstripeframework*cpe:2.3:a:silverstripe:framework:*:*:*:*:*:*:*:*
silverstripeframework*cpe:2.3:a:silverstripe:framework:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "silverstripe",
    "product": "silverstripe-framework",
    "versions": [
      {
        "version": "< 4.13.39",
        "status": "affected"
      },
      {
        "version": ">= 5.0.0, < 5.1.11",
        "status": "affected"
      }
    ]
  }
]

4.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

4.3 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

14.2%