CVE-2011-4962: Silverstripe
Medium severity, CVSS 6.8. EPSS: 3.9% chance of exploitation in the next 30 days.
code/sitefeatures/PageCommentInterface.php in SilverStripe 2.4.x before 2.4.6 might allow remote attackers to execute arbitrary code via a crafted cookie in a user comment submission, which is not properly handled when it is deserialized.
Affected products
- Silverstripe Silverstripe: version 2.4.0 only; version 2.4.1 only; version 2.4.2 only; version 2.4.3 only; version 2.4.4 only; version 2.4.5 only
Published 2012-09-17. Last modified 2026-06-16.