6
CVSSv2

CVE-2011-4961

Published: 17/09/2012 Updated: 15/10/2012
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
VMScore: 534
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

SilverStripe 2.3.x prior to 2.3.12 and 2.4.x prior to 2.4.6 allows remote authenticated users with the EDIT_PERMISSIONS permission to gain administrator privileges via a TreeMultiselectField that includes admin groups when adding a user to the selected groups.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

silverstripe silverstripe 2.3.4

silverstripe silverstripe 2.3.5

silverstripe silverstripe 2.3.6

silverstripe silverstripe 2.3.7

silverstripe silverstripe 2.3.0

silverstripe silverstripe 2.3.2

silverstripe silverstripe 2.3.9

silverstripe silverstripe 2.3.11

silverstripe silverstripe 2.3.1

silverstripe silverstripe 2.3.3

silverstripe silverstripe 2.3.8

silverstripe silverstripe 2.3.10

silverstripe silverstripe 2.4.0

silverstripe silverstripe 2.4.1

silverstripe silverstripe 2.4.2

silverstripe silverstripe 2.4.3

silverstripe silverstripe 2.4.5

silverstripe silverstripe 2.4.4