
Cloud Vulnerability DB
A community-led vulnerabilities database
A vulnerability in SiteTree object creation permission validation was identified in Silverstripe CMS (GHSA-3mm9-2p44-rw39). The vulnerability affects versions 3.1.0-3.1.10, 3.1.11-rc1, and 3.0.11 and below, and was fixed in versions 3.0.12 and 3.1.11. The issue was disclosed on March 19, 2015. The vulnerability exists in the SiteTree::canCreate method where user permissions are not properly validated by default unless overridden by user code or configuration system (Silverstripe Advisory).
The vulnerability allows unauthorized users to create new SiteTree objects in the database due to improper permission validation in the default implementation of SiteTree::canCreate method. The issue has been assigned a High severity rating with a CVSS score of 7.5. The vulnerability is particularly concerning when users are given CMS access through other means or when using modules like RestfulServer that rely on model-level permission checks (GitHub Advisory).
The vulnerability allows both authenticated users with limited privileges and unauthenticated guests to create new pages in the CMS database. However, the scope is limited to creation of draft or live pages only - affected users cannot edit, publish, or unpublish existing pages. The impact is significant for systems that rely on proper permission validation for page creation (Silverstripe Advisory).
The vulnerability can be exploited in two scenarios: 1) When users are given CMS access through alternative means, or 2) When using modules like RestfulServer that depend on model-level permission checks. The attack requires network access but no special privileges or user interaction (GitHub Advisory).
The vulnerability has been fixed in Silverstripe CMS versions 3.0.12 and 3.1.11. All users are strongly advised to upgrade to these patched versions as soon as possible. The fix involves proper implementation of permission validation in the SiteTree::canCreate method (Silverstripe Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."