PT-2015-6760 · Silverstripe · Silverstripe/Framework
Hyp3Rlinx
·
Publicado
2015-06-24
·
Atualizado
2022-05-14
·
CVE-2015-5062
CVSS v2.0
5.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
SilverStripe CMS & Framework version 3.1.13
Description
The issue allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks. This is achieved by manipulating a URL in the
returnURL parameter to the /dev/build API endpoint.Recommendations
For SilverStripe CMS & Framework version 3.1.13, consider restricting access to the
returnURL parameter in the /dev/build API endpoint to minimize the risk of exploitation. As a temporary workaround, avoid using the returnURL parameter in the affected API endpoint until the issue is resolved.Exploit
Correção
Open Redirect
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Silverstripe/Framework