{"id":"CVE-2019-5715","aliases":["GHSA-wvfw-w3x6-g526"],"url":"https://o3.security/vulnerability/CVE-2019-5715","summary":"Silverstripe Framework SQLi Vulnerability","details":"All versions of SilverStripe 3 prior to 3.6.7 and 3.7.3, and all versions of SilverStripe 4 prior to 4.0.7, 4.1.5, 4.2.4, and 4.3.1 allows Reflected SQL Injection through Form and DataObject.","published":"2019-04-11T19:29:01.287Z","modified":"2026-08-07T16:35:23.501457Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"silverstripe/framework","fixedVersion":"3.6.7"},{"ecosystem":"Packagist","name":"silverstripe/framework","fixedVersion":"4.0.7"},{"ecosystem":"Packagist","name":"silverstripe/framework","fixedVersion":"3.7.3"},{"ecosystem":"Packagist","name":"silverstripe/framework","fixedVersion":"4.1.5"},{"ecosystem":"Packagist","name":"silverstripe/framework","fixedVersion":"4.2.4"},{"ecosystem":"Packagist","name":"silverstripe/framework","fixedVersion":"4.3.1"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://www.silverstripe.org/download/security-releases/"},{"type":"ADVISORY","url":"https://www.silverstripe.org/download/security-releases/ss-2018-021"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T16:35:23.501457Z"}}