silverstripeCMS Permissions Privileges and Access Controls Vulnerability - CVE-2011-4961 - Vulnerability Database

silverstripeCMS Permissions Privileges and Access Controls Vulnerability - CVE-2011-4961

Medium
Reference: CVE-2011-4961
Title: silverstripeCMS Permissions Privileges and Access Controls Vulnerability
Overview:

SilverStripe 2.3.x before 2.3.12 and 2.4.x before 2.4.6 allows remote authenticated users with the EDIT_PERMISSIONS permission to gain administrator privileges via a TreeMultiselectField that includes admin groups when adding a user to the selected groups.