-
CVSS Score
-| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| silverstripe/framework | composer | <= 3.1.11 | 3.1.12 |
The vulnerability stems from improper XML parsing safeguards. The pre-patch version of xml2array in Convert.php directly instantiated SimpleXMLElement without:
A Semantic Attack on Google Gemini - Read the Latest Research