Cross-site request forgery In silverstripe/framework
Description
Open redirect vulnerability on CMSSecurity relogin screen An attacker can display a link to a third party website on a login screen by convincing a legitimate content author to follow a specially crafted link.
Upgrade to silverstripe/framework 4.12.5 or above to remedy the vulnerability.
Reporter: Matthew Dekker
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
packagist | 4.12.5 |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3. 4.