PT-2012-1330 · Silverstripe · Silverstripe

Henri Salo

·

Published

2012-08-26

·

Updated

2012-08-27

·

CVE-2010-5087

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions SilverStripe versions 2.3.x through 2.3.9 SilverStripe versions 2.4.x through 2.4.3
Description The issue allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism and hijack the authentication of administrators. This is achieved via vectors related to "form action requests" using a controller.
Recommendations For SilverStripe versions 2.3.x through 2.3.9, update to version 2.3.10 to resolve the issue. For SilverStripe versions 2.4.x through 2.4.3, update to version 2.4.4 to resolve the issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-5087

Affected Products

Silverstripe