Description
In SilverStripe through 4.6.0-rc1, a FormField with square brackets in the field name skips validation.
Remediation
References
Related Vulnerabilities
Ruby Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-3655)
Apache HTTP Server NULL Pointer Dereference Vulnerability (CVE-2018-8011)
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2013-1817)
WordPress Plugin Social Sharing-Sassy Social Share Cross-Site Scripting (3.3.3)