Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-v68g-62v9-39w5: Unpublished, protected files can be published via shortcode

Draft protected images can be published by changing an existing image shortcode on website content to match the ID of the draft protected image and then publishing the website content.

ghsa
#web#git

Unpublished, protected files can be published via shortcode

Moderate severity GitHub Reviewed Published Jun 29, 2022 • Updated Jun 29, 2022

Related news

CVE-2022-29858: Security Releases

Silverstripe silverstripe/assets through 1.10 allows XSS.