CVE Vulnerabilities

CVE-2011-4961

Published: Sep 17, 2012 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

SilverStripe 2.3.x before 2.3.12 and 2.4.x before 2.4.6 allows remote authenticated users with the EDIT_PERMISSIONS permission to gain administrator privileges via a TreeMultiselectField that includes admin groups when adding a user to the selected groups.

Affected Software

NameVendorStart VersionEnd Version
SilverstripeSilverstripe2.3.0 (including)2.3.0 (including)
SilverstripeSilverstripe2.3.1 (including)2.3.1 (including)
SilverstripeSilverstripe2.3.2 (including)2.3.2 (including)
SilverstripeSilverstripe2.3.3 (including)2.3.3 (including)
SilverstripeSilverstripe2.3.4 (including)2.3.4 (including)
SilverstripeSilverstripe2.3.5 (including)2.3.5 (including)
SilverstripeSilverstripe2.3.6 (including)2.3.6 (including)
SilverstripeSilverstripe2.3.7 (including)2.3.7 (including)
SilverstripeSilverstripe2.3.8 (including)2.3.8 (including)
SilverstripeSilverstripe2.3.9 (including)2.3.9 (including)
SilverstripeSilverstripe2.3.10 (including)2.3.10 (including)
SilverstripeSilverstripe2.3.11 (including)2.3.11 (including)

References