{"id":"CVE-2011-4962","aliases":[],"url":"https://o3.security/vulnerability/CVE-2011-4962","summary":"Silverstripe CMS Arbitrary Code Execution","details":"`code/sitefeatures/PageCommentInterface.php` in SilverStripe 2.4.x before 2.4.6 might allow remote attackers to execute arbitrary code via a crafted cookie in a user comment submission, which is not properly handled when it is deserialized.","published":"2022-05-17T05:22:06Z","modified":"2024-01-19T17:58:29.247067Z","cvss":null,"epss":{"score":0.03918,"percentile":0.89819,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"silverstripe/cms","fixedVersion":"2.4.6"}],"fix":{"url":"https://github.com/silverstripe/silverstripe-cms/commit/d15e8509b01ff2dbbe3028a055021a29b1065b22","label":"silverstripe/silverstripe-cms@d15e850"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2011-4962"},{"type":"WEB","url":"https://github.com/silverstripe/silverstripe-cms/commit/d15e8509b01ff2dbbe3028a055021a29b1065b22"},{"type":"PACKAGE","url":"https://github.com/silverstripe/silverstripe-cms"},{"type":"WEB","url":"https://web.archive.org/web/20120621234353/http://doc.silverstripe.org/framework/en/trunk/changelogs/2.4.6"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2012/04/30/1"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2012/04/30/3"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-01-19T17:58:29.247067Z"}}