-
CVSS Score
-The vulnerability is related to the Member.Name being used in a template without proper escaping. The patches modify the Member class to properly cast the Name property. The getName() method is directly related to the vulnerability as it returns the raw FirstName and Surname.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| silverstripe/framework | composer | >= 3.1.9-rc1, < 3.1.20 | 3.1.20 |
| silverstripe/framework | composer | >= 3.2.4-rc1, < 3.2.5 | 3.2.5 |
| silverstripe/framework | composer | >= 3.3.2-rc1, < 3.3.3 | 3.3.3 |
| silverstripe/framework | composer | >= 3.4.0-rc1, < 3.4.1 | 3.4.1 |
A Semantic Attack on Google Gemini - Read the Latest Research