Vulnerability DatabaseGHSA-3mm9-2p44-rw39

GHSA-3mm9-2p44-rw39
PHP vulnerability analysis and mitigation

Overview

A vulnerability in SiteTree object creation permission validation was identified in Silverstripe CMS (GHSA-3mm9-2p44-rw39). The vulnerability affects versions 3.1.0-3.1.10, 3.1.11-rc1, and 3.0.11 and below, and was fixed in versions 3.0.12 and 3.1.11. The issue was disclosed on March 19, 2015. The vulnerability exists in the SiteTree::canCreate method where user permissions are not properly validated by default unless overridden by user code or configuration system (Silverstripe Advisory).

Technical details

The vulnerability allows unauthorized users to create new SiteTree objects in the database due to improper permission validation in the default implementation of SiteTree::canCreate method. The issue has been assigned a High severity rating with a CVSS score of 7.5. The vulnerability is particularly concerning when users are given CMS access through other means or when using modules like RestfulServer that rely on model-level permission checks (GitHub Advisory).

Impact

The vulnerability allows both authenticated users with limited privileges and unauthenticated guests to create new pages in the CMS database. However, the scope is limited to creation of draft or live pages only - affected users cannot edit, publish, or unpublish existing pages. The impact is significant for systems that rely on proper permission validation for page creation (Silverstripe Advisory).

Exploitability

The vulnerability can be exploited in two scenarios: 1) When users are given CMS access through alternative means, or 2) When using modules like RestfulServer that depend on model-level permission checks. The attack requires network access but no special privileges or user interaction (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been fixed in Silverstripe CMS versions 3.0.12 and 3.1.11. All users are strongly advised to upgrade to these patched versions as soon as possible. The fix involves proper implementation of permission validation in the SiteTree::canCreate method (Silverstripe Advisory).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-44741HIGH8.8
  • PHP logoPHP
  • pimcore/admin-ui-classic-bundle
NoYesAug 12, 2026
CVE-2026-47233MEDIUM6.5
  • PHP logoPHP
  • admidio/admidio
NoYesAug 12, 2026
CVE-2026-47132MEDIUM5.4
  • PHP logoPHP
  • thorsten/phpmyfaq
NoYesAug 12, 2026
CVE-2026-47234MEDIUM4.4
  • PHP logoPHP
  • admidio/admidio
NoYesAug 12, 2026
CVE-2026-49262LOW3
  • PHP logoPHP
  • aimeos/pagible
NoYesAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management