← Terug naar overzicht

A server-side template injection vulnerability exists in Silverstripe Advanced Workflow module prior to versions 6.4.5, 7.1.3, and 7.2.1. An attacker with permission to author advanced workflow email templates can inject a malicious payload into the NotifyUsersWorkflowAction.EmailTemplate field. When rendered by the SSTemplateParser template engine, the payload can trigger PHP evaluation and arbitrary code execution on the server. The vulnerability requires the attacker to have template authoring permissions, limiting the attack surface but not eliminating risk in multi-user environments. Fixes have been released in versions 6.4.5, 7.1.3, and 7.2.1. Regression test coverage has been added in tests/php/WorkflowEngineTest.php. Users are strongly advised to upgrade to the patched versions immediately.

Affected products

  • Silverstripe Advanced Workflow 6.x prior to 6.4.5
  • Silverstripe Advanced Workflow 7.1.x prior to 7.1.3
  • Silverstripe Advanced Workflow 7.2.x prior to 7.2.1

Related CVE's

  • CVE-2026-54718

Categories

  • Enterprise Applications
  • Web Technologies