Headline
GHSA-v68g-62v9-39w5: Unpublished, protected files can be published via shortcode
Draft protected images can be published by changing an existing image shortcode on website content to match the ID of the draft protected image and then publishing the website content.
Unpublished, protected files can be published via shortcode
Moderate severity GitHub Reviewed Published Jun 29, 2022 • Updated Jun 29, 2022
Related news
CVE-2022-29858: Security Releases
Silverstripe silverstripe/assets through 1.10 allows XSS.