{"id":"GHSA-xx4r-5265-48j6","aliases":[],"url":"https://o3.security/vulnerability/GHSA-xx4r-5265-48j6","summary":"silverstripe/framework SQL injection in full text search ","details":"When performing a fulltext search in SilverStripe 4.0.0 the 'start' querystring parameter is never escaped safely. This exposes a possible SQL injection vulnerability.\n\nThe issue exists in 3.5 and 3.6 but is less vulnerable, as SearchForm sanitises these variables prior to passing to mysql.","published":"2024-05-27T21:53:32Z","modified":"2024-12-02T05:45:12.144848Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"silverstripe/framework","fixedVersion":"3.5.6"},{"ecosystem":"Packagist","name":"silverstripe/framework","fixedVersion":"3.6.3"},{"ecosystem":"Packagist","name":"silverstripe/framework","fixedVersion":"4.0.1"}],"fix":{"url":"https://github.com/silverstripe/silverstripe-framework/commit/099a5a3c2d99ed39bdd8815e1e2790bb9351770b","label":"silverstripe/silverstripe-framework@099a5a3"},"references":[{"type":"WEB","url":"https://github.com/silverstripe/silverstripe-framework/commit/099a5a3c2d99ed39bdd8815e1e2790bb9351770b"},{"type":"WEB","url":"https://github.com/silverstripe/silverstripe-framework/commit/a8465900bdc77199176c953890ce7587045b1ea4"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/framework/SS-2017-008-1.yaml"},{"type":"PACKAGE","url":"https://github.com/silverstripe/silverstripe-framework"},{"type":"WEB","url":"https://www.silverstripe.org/download/security-releases/ss-2017-008"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-02T05:45:12.144848Z"}}