CVE-2019-5715: Silverstripe
Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.
All versions of SilverStripe 3 prior to 3.6.7 and 3.7.3, and all versions of SilverStripe 4 prior to 4.0.7, 4.1.5, 4.2.4, and 4.3.1 allows Reflected SQL Injection through Form and DataObject.
Affected products
- Silverstripe Silverstripe: from 3.0.0, before 3.6.7 (fixed in 3.6.7); from 3.7.0, before 3.7.3 (fixed in 3.7.3); from 4.0.0, before 4.0.7 (fixed in 4.0.7); from 4.1.0, before 4.1.5 (fixed in 4.1.5); from 4.2.0, before 4.2.4 (fixed in 4.2.4); version 4.3.0 only
Published 2019-04-11. Last modified 2026-06-17.