PT-2024-40294 · Packagist · Silverstripe/Framework

Published

2024-05-27

·

Updated

2024-05-27

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: No specific software or versions mentioned, so: Software (affected versions not specified)
Description: The issue concerns a user ID enumeration vulnerability in brute force error messages. It allows an attacker to infer or confirm user details that exist in the member table by exploiting the difference in login attempt logging and lockout processes for non-existent and existent users. This vulnerability has been resolved by ensuring that the login attempt logging and lockout process works equivalently for both non-existent and existent users.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Weakness Enumeration

Related Identifiers

GHSA-G84Q-CQ55-XWGP

Affected Products

Silverstripe/Framework