Missing permission check of canView in GridFieldPrintButton
Moderate severity
GitHub Reviewed
Published
Apr 26, 2023
in
silverstripe/silverstripe-framework
•
Updated Nov 12, 2023
Description
Published by the National Vulnerability Database
Apr 26, 2023
Published to the GitHub Advisory Database
Apr 26, 2023
Reviewed
Apr 26, 2023
Last updated
Nov 12, 2023
The GridField print view incorrectly validates the permission of DataObjects potentially allowing a content author to view records they are not authorised to access.
Upgrade to
silverstripe/framework
4.12.5 or above to address the issue.Reported by Stephan Bauer from relaxt Webdienstleistungsagentur GmbH
References