Vulnerability Description
SQL injection vulnerability in silverstripe/restfulserver module 1.0.x before 1.0.9, 2.0.x before 2.0.4, and 2.1.x before 2.1.2 and silverstripe/registry module 2.1.x before 2.1.1 and 2.2.x before 2.2.1 allows attackers to execute arbitrary SQL commands.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Silverstripe | Registry | >= 2.1.0, < 2.1.1 |
| Silverstripe | Restfulserver | >= 1.0.1, < 1.0.9 |
Related Weaknesses (CWE)
References
- https://www.silverstripe.org/download/security-releases/cve-2019-12149Vendor Advisory
- https://www.silverstripe.org/download/security-releases/cve-2019-12149Vendor Advisory
FAQ
What is CVE-2019-12149?
CVE-2019-12149 is a vulnerability with a CVSS score of 9.8 (CRITICAL). SQL injection vulnerability in silverstripe/restfulserver module 1.0.x before 1.0.9, 2.0.x before 2.0.4, and 2.1.x before 2.1.2 and silverstripe/registry module 2.1.x before 2.1.1 and 2.2.x before 2.2...
How severe is CVE-2019-12149?
CVE-2019-12149 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-12149?
Check the references section above for vendor advisories and patch information. Affected products include: Silverstripe Registry, Silverstripe Restfulserver.