VDB
HIGH 8.8

GHSA-g8wr-r2v2-vqc6

silverstripe/userforms vulnerable to remote code execution via userforms email subject

Quick fix

GHSA-g8wr-r2v2-vqc6 — silverstripe/userforms: upgrade to the fixed version with the command below.

composer require silverstripe/userforms:^6.4.9

Details

### Impact The userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server.

### Reported by Jack Wallace from Bastion Security

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist / silverstripe/userforms
Introduced in: 0 Fixed in: 6.4.9
Fix composer require silverstripe/userforms:^6.4.9
Packagist / silverstripe/userforms
Introduced in: 7.0.0 Fixed in: 7.0.7
Fix composer require silverstripe/userforms:^7.0.7
Packagist / silverstripe/userforms
Introduced in: 7.1.0 Fixed in: 7.1.1
Fix composer require silverstripe/userforms:^7.1.1

References