Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Nate Devereux

Researcher fromSilverstripe Ltd.
#47683of 53,633
5.3Total CVSS
Vulnerabilities · 1
PT-2024-23108
5.3
2024-07-17
Silverstripe · Silverstripe/Reports · CVE-2024-29885
**Name of the Vulnerable Software and Affected Versions** silverstripe/reports versions prior to 5.2.3 **Description** The issue allows reports to be accessed by their direct URL by any user who has access to view the reports admin section, even if the `canView()` method for that report returns `false`. **Recommendations** For versions prior to 5.2.3, upgrade to version 5.2.3 to resolve the issue. As a temporary workaround, consider restricting access to the reports admin section to minimize the risk of exploitation.