{"id":"GHSA-vj2j-6g3w-4662","aliases":[],"url":"https://o3.security/vulnerability/GHSA-vj2j-6g3w-4662","summary":"Silverstripe Missing CSRF protection in login form","details":"LoginForm calls disableSecurityToken(), which causes a \"shared host domain\" vulnerability: http://stackoverflow.com/a/15350123.","published":"2024-05-23T19:41:41Z","modified":"2024-11-28T05:31:51.042310Z","cvss":{"score":5.4,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"silverstripe/framework","fixedVersion":"3.1.19"},{"ecosystem":"Packagist","name":"silverstripe/framework","fixedVersion":"3.2.4"},{"ecosystem":"Packagist","name":"silverstripe/framework","fixedVersion":"3.3.2"}],"fix":{"url":"https://github.com/silverstripe/silverstripe-framework/commit/a6bd22ab2f3b11a054d20be13306a19089510989","label":"silverstripe/silverstripe-framework@a6bd22a"},"references":[{"type":"WEB","url":"https://github.com/silverstripe/silverstripe-framework/commit/a6bd22ab2f3b11a054d20be13306a19089510989"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/framework/SS-2016-006-1.yaml"},{"type":"PACKAGE","url":"https://github.com/silverstripe/silverstripe-framework"},{"type":"WEB","url":"https://stackoverflow.com/questions/6412813/do-login-forms-need-tokens-against-csrf-attacks/15350123#15350123"},{"type":"WEB","url":"https://www.silverstripe.org/download/security-releases/ss-2016-006"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-11-28T05:31:51.042310Z"}}