Arbitrary SQL Command Execution in SilverStripe Folder::findOrMake Method

Arbitrary SQL Command Execution in SilverStripe Folder::findOrMake Method

CVE-2011-4960 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

SQL injection vulnerability in the Folder::findOrMake method in SilverStripe 2.3.x before 2.3.12 and 2.4.x before 2.4.6 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Learn more about our Web Application Penetration Testing UK.