PT-2024-40027 · Silverstripe · Silverstripe Cms

Published

2024-05-23

·

Updated

2024-05-23

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Silverstripe CMS (affected versions not specified)
Description The issue concerns insufficient CSRF protection in GridField, which can be exploited to trick users with CMS access into posting unspecified data from external websites. This affects the management of groups, users, and permissions in the CMS.
Recommendations For the affected versions, ensure that all gridFieldAlterAction submissions are checked for the SecurityID token during submission.

Fix

CSRF

Weakness Enumeration

Related Identifiers

GHSA-2HPC-MF4Q-J885

Affected Products

Silverstripe Cms