PT-2024-40248 · Unknown · Silverstripe

Published

2024-05-27

·

Updated

2024-05-27

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Silverstripe (affected versions not specified)
Description: The issue concerns a user ID enumeration vulnerability in brute force error messages. Specifically, the system previously handled login attempts for non-existent and existing users differently, allowing an attacker to infer or confirm user details that exist in the member table. This was possible because users that don't exist would never receive a locked-out message, while existing users would. The estimated number of potentially affected devices worldwide is not available. There is no information about real-world incidents where this issue was exploited.
Recommendations: To resolve the issue, ensure that the login attempt logging and lockout process works equivalently for non-existent users as it does for existing users. This change should be applied to prevent user ID enumeration through brute force error messages. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Weakness Enumeration

Related Identifiers

GHSA-CRR3-H4M8-7F56

Affected Products

Silverstripe