Advisory Database
  • Advisories
  • Dependency Scanning
  1. composer
  2. ›
  3. symbiote/silverstripe-multivaluefield
  4. ›
  5. GHSA-g5vj-wj9x-4jg9

GHSA-g5vj-wj9x-4jg9: symbiote/silverstripe-multivaluefield Possible PHP Object Injection via Multi-Value Field Extension

May 29, 2024

A potential deserialisation vulnerability has been identified in the symbiote/silverstripe-multivaluefield which could allow an attacker to exploit implementations of this module via object injection.

Support for handling PHP objects as values in this module has been deprecated, and the serialisation technique has been switched to using JSON for handling arrays.

As well as this, a potential XSS (cross-site scripting) vulnerability has been identified and remediated.

References

  • github.com/FriendsOfPHP/security-advisories/blob/master/symbiote/silverstripe-multivaluefield/SS-2018-017-1.yaml
  • github.com/advisories/GHSA-g5vj-wj9x-4jg9
  • github.com/symbiote/silverstripe-multivaluefield
  • github.com/symbiote/silverstripe-multivaluefield/commit/31fbc8c208431fc7d7e96da6fa39ca057d978953
  • github.com/symbiote/silverstripe-multivaluefield/commit/f523dfcb13b2bd9eb110ffa0c83087a49322ad3b
  • www.silverstripe.org/download/security-releases/ss-2018-017

Code Behaviors & Features

Detect and mitigate GHSA-g5vj-wj9x-4jg9 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 3.0.0 before 3.1.0

Fixed versions

  • 3.1.0

Solution

Upgrade to version 3.1.0 or above.

Impact 6.1 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Learn more about CVSS

Weakness

  • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Source file

packagist/symbiote/silverstripe-multivaluefield/GHSA-g5vj-wj9x-4jg9.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:16:16 +0000.