PT-2024-40446 · Packagist · Silverstripe/Framework

Published

2024-05-27

·

Updated

2024-05-27

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions No specific software or versions mentioned
Description The issue allows extraction of pre-configured database or default admin account passwords by viewing the source of the page and inspecting the value property of the password fields when accessing the install.php script.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Weakness Enumeration

Related Identifiers

GHSA-R3PR-FH25-WRFC

Affected Products

Silverstripe/Framework