漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Record titles for restricted records can be viewed if exposed by GridFieldAddExistingAutocompleter
Vulnerability Description
Silverstripe Framework is the framework that forms the base of the Silverstripe content management system. Prior to versions 4.13.39 and 5.1.11, if a user should not be able to see a record, but that record can be added to a `GridField` using the `GridFieldAddExistingAutocompleter` component, the record's title can be accessed by that user. Versions 4.13.39 and 5.1.11 contain a fix for this issue.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
信息暴露
Vulnerability Title
Silverstripe Framework 安全漏洞
Vulnerability Description
silverstripe framework是一套CMS网站框架。 Silverstripe Framework 4.13.39之前的4.x版本和5.1.11之前的5.x版本存在安全漏洞,该漏洞源于用户可以访问无权查看的记录标题。
CVSS Information
N/A
Vulnerability Type
N/A