VDB
Sign up
HIGH8.8

GHSA-xc69-p8fc-m6m5

silverstripe/subsites Unsafe SQL Query Construction (Safe Data Source)

Quick fix

GHSA-xc69-p8fc-m6m5 — silverstripe/subsites: upgrade to the fixed version with the command below.

composer require silverstripe/subsites:^2.1.1

Details

There is a low level potential SQL injection vulnerability in the silverstripe/subsites module has been identified and fixed in version 2.1.1.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/silverstripe/subsites
Introduced in: 2.0.0Fixed in: 2.1.1
Fixcomposer require silverstripe/subsites:^2.1.1

References