{"id":"GHSA-265q-222x-52m6","summary":"silverstripe/framework has potential SQL Injection vulnerability in PostgreSQL database connector","details":"A potential SQL injection vulnerability was identified by using the silverstripe/postgresql database adapter. While unlikely to be exploitable, we have patched silverstripe/framework to ensure that table names are safely escaped before being passed to database adapters or user code.","modified":"2024-12-03T06:23:59.669492Z","published":"2024-05-28T13:01:48Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2024-05-28T13:01:48Z","nvd_published_at":null,"cwe_ids":["CWE-89"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/silverstripe/silverstripe-framework/commit/48bd335648188df9dae72be1e5f9c808f3fe1e77"},{"type":"WEB","url":"https://github.com/silverstripe/silverstripe-framework/commit/fecedc2d98eeaaff6424fb59dc70ef6bdc6dc92d"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/framework/SS-2018-020-1.yaml"},{"type":"PACKAGE","url":"https://github.com/silverstripe/silverstripe-framework"},{"type":"WEB","url":"https://www.silverstripe.org/download/security-releases/ss-2018-020"}],"affected":[{"package":{"name":"silverstripe/framework","ecosystem":"Packagist","purl":"pkg:composer/silverstripe/framework"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.0.0-rc1"},{"fixed":"4.0.6"}]}],"versions":["4.0.0","4.0.0-rc1","4.0.0-rc2","4.0.0-rc3","4.0.1","4.0.1-rc1","4.0.2","4.0.3","4.0.4","4.0.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-265q-222x-52m6/GHSA-265q-222x-52m6.json"}},{"package":{"name":"silverstripe/framework","ecosystem":"Packagist","purl":"pkg:composer/silverstripe/framework"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.1.0-rc1"},{"fixed":"4.1.4"}]}],"versions":["4.1.0","4.1.0-rc1","4.1.0-rc2","4.1.1","4.1.2","4.1.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-265q-222x-52m6/GHSA-265q-222x-52m6.json"}},{"package":{"name":"silverstripe/framework","ecosystem":"Packagist","purl":"pkg:composer/silverstripe/framework"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.2.0-rc1"},{"fixed":"4.2.3"}]}],"versions":["4.2.0","4.2.1","4.2.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-265q-222x-52m6/GHSA-265q-222x-52m6.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}