CVE-2011-4962

EPSS 2.7%

Silverstripe CMS Arbitrary Code Execution

發布日:2022/5/17修改日:2024/1/19

描述

`code/sitefeatures/PageCommentInterface.php` in SilverStripe 2.4.x before 2.4.6 might allow remote attackers to execute arbitrary code via a crafted cookie in a user comment submission, which is not properly handled when it is deserialized.

受影響套件(1)

參考連結(6)