CVE-2019-12149: Silverstripe Registry
Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.
SQL injection vulnerability in silverstripe/restfulserver module 1.0.x before 1.0.9, 2.0.x before 2.0.4, and 2.1.x before 2.1.2 and silverstripe/registry module 2.1.x before 2.1.1 and 2.2.x before 2.2.1 allows attackers to execute arbitrary SQL commands.
Affected products
- Silverstripe Registry: from 2.1.0, before 2.1.1 (fixed in 2.1.1); from 2.2.0, before 2.2.1 (fixed in 2.2.1)
- Silverstripe Restfulserver: from 1.0.1, before 1.0.9 (fixed in 1.0.9); from 2.0.0, before 2.0.4 (fixed in 2.0.4)
Published 2019-06-11. Last modified 2026-06-17.