{"id":"CVE-2019-12203","aliases":["GHSA-w7r7-r8r9-vrg2"],"url":"https://o3.security/vulnerability/CVE-2019-12203","summary":"Session fixation in change password form","details":"SilverStripe through 4.3.3 allows session fixation in the \"change password\" form.","published":"2019-09-25T19:15:10.187Z","modified":"2026-08-07T15:00:03.500877Z","cvss":{"score":6.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Packagist","name":"silverstripe/framework","fixedVersion":"3.7.4"},{"ecosystem":"Packagist","name":"silverstripe/framework","fixedVersion":"4.4.4"},{"ecosystem":"Packagist","name":"silverstripe/framework","fixedVersion":"3.6.8"},{"ecosystem":"Packagist","name":"silverstripe/framework","fixedVersion":"4.3.5"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://forum.silverstripe.org/c/releases"},{"type":"ADVISORY","url":"https://www.silverstripe.org/download/security-releases/"},{"type":"ADVISORY","url":"https://www.silverstripe.org/download/security-releases/CVE-2019-12203"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T15:00:03.500877Z"}}