PT-2024-40027 · Silverstripe · Silverstripe Cms
Published
2024-05-23
·
Updated
2024-05-23
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Silverstripe CMS (affected versions not specified)
Description
The issue concerns insufficient CSRF protection in GridField, which can be exploited to trick users with CMS access into posting unspecified data from external websites. This affects the management of groups, users, and permissions in the CMS.
Recommendations
For the affected versions, ensure that all gridFieldAlterAction submissions are checked for the
SecurityID token during submission.Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Silverstripe Cms