HIGH8.8
GHSA-xc69-p8fc-m6m5
silverstripe/subsites Unsafe SQL Query Construction (Safe Data Source)
Quick fix
GHSA-xc69-p8fc-m6m5 — silverstripe/subsites: upgrade to the fixed version with the command below.
composer require silverstripe/subsites:^2.1.1Details
There is a low level potential SQL injection vulnerability in the silverstripe/subsites module has been identified and fixed in version 2.1.1.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/silverstripe/subsites
Introduced in:
2.0.0Fixed in: 2.1.1Fix
composer require silverstripe/subsites:^2.1.1References
- https://github.com/silverstripe/silverstripe-subsites/commit/bf2c81dce62ae9a7623d224fd31a39505260eb57[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/subsites/SS-2018-016-1.yaml[WEB]
- https://github.com/silverstripe/silverstripe-subsites[PACKAGE]
- https://www.silverstripe.org/download/security-releases/ss-2018-016[WEB]