PT-2024-23108 · Silverstripe · Silverstripe/Reports

Fiona Black

+1

·

Published

2024-07-17

·

Updated

2024-07-18

·

CVE-2024-29885

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions silverstripe/reports versions prior to 5.2.3
Description The issue allows reports to be accessed by their direct URL by any user who has access to view the reports admin section, even if the canView() method for that report returns false.
Recommendations For versions prior to 5.2.3, upgrade to version 5.2.3 to resolve the issue. As a temporary workaround, consider restricting access to the reports admin section to minimize the risk of exploitation.

Exploit

Fix

Incorrect Authorization

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2024-29885
GHSA-89Q6-98XX-4FFW

Affected Products

Silverstripe/Reports