PT-2024-40483 · Silverstripe · Silverstripe/Framework

Published

2024-05-23

·

Updated

2024-05-23

CVSS v3.1

5.8

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions SilverStripe framework (affected versions not specified)
Description A issue has been found in the SilverStripe framework where a login URL can be potentially redirected to an external site. For instance, a URL like http://www.my-silverstripe-site.com/Security/login?BackURL=/attacker-site.com will redirect successful logins to the page http://attacker-site.com. This could be exploited by setting up a website that looks identical to the original, prompting the user to enter their credentials again if they see a "login failed" message.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Open Redirect

Weakness Enumeration

Related Identifiers

GHSA-VP8P-C6XJ-XPJ7

Affected Products

Silverstripe/Framework