CyberRota Analysis
AI-GeneratedSilverstripe UserForms versions 6.0.0 to 6.4.9, 7.0.7, and 7.1.1 are vulnerable due to a flaw in the email recipient subject field, which allows authenticated users to inject and execute arbitrary server-side code. This vulnerability poses a significant risk to the confidentiality, integrity, and availability of the system. Organizations using affected versions should prioritize updating to the patched releases to mitigate potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Silverstripe UserForms provides a visual form builder for the Silverstripe CMS. From 6.0.0 until 6.4.9, 7.0.7, and 7.1.1, the userform email recipient subject field in the CMS accepts a specially crafted payload that can be interpreted as executable server-side code. An authenticated CMS user with permission to configure a UserForms email recipient can use the subject field to run arbitrary code on the server, compromising confidentiality, integrity, and availability. This issue is fixed in versions 6.4.9, 7.0.7, and 7.1.1.