PT-2024-40363 · Packagist · Silverstripe/Framework

Published

2024-05-27

·

Updated

2024-05-27

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions No specific software or versions mentioned.
Description A maliciously crafted URL can bypass the offsite redirection protection for BackURL parameters, potentially leading to users entering sensitive data on malicious websites instead of the intended one.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Open Redirect

Weakness Enumeration

Related Identifiers

GHSA-M5Q3-MVCR-GC5M

Affected Products

Silverstripe/Framework