logo

Database

Cross-site request forgery In silverstripe/framework

Description

Open redirect vulnerability on CMSSecurity relogin screen An attacker can display a link to a third party website on a login screen by convincing a legitimate content author to follow a specially crafted link.

Upgrade to silverstripe/framework 4.12.5 or above to remedy the vulnerability.

Reporter: Matthew Dekker

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions
FLAT-325A4 – Vulnerability | Fluid Attacks Database