{"id":"GHSA-w8fq-xgvh-cxc2","aliases":[],"url":"https://o3.security/vulnerability/GHSA-w8fq-xgvh-cxc2","summary":"Silverstripe Forum Module CSRF Vulnerability","details":"A number of form actions in the Forum module are directly accessible. A malicious user (e.g. spammer) can use GET requests to create Members and post to forums, bypassing CSRF and anti-spam measures.\n\nAdditionally, a forum moderator could be tricked into clicking a specially crafted URL, resulting in a topic being moved.\n\nThanks to Michael Strong for discovering.","published":"2024-05-23T14:41:16Z","modified":"2024-11-28T05:41:04.292453Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"silverstripe/forum","fixedVersion":"0.6.2"},{"ecosystem":"Packagist","name":"silverstripe/forum","fixedVersion":"0.7.4"}],"fix":{"url":"https://github.com/silverstripe-archive/silverstripe-forum/commit/0ec7c92785f36c8edf4a11c36a4fc27e0c40cee6","label":"silverstripe-archive/silverstripe-forum@0ec7c92"},"references":[{"type":"WEB","url":"https://github.com/silverstripe-archive/silverstripe-forum/commit/0ec7c92785f36c8edf4a11c36a4fc27e0c40cee6"},{"type":"WEB","url":"https://github.com/silverstripe-archive/silverstripe-forum/commit/efe09f95ccdb0138ce5bd3d3a21b3d9e97038dd8"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/forum/SS-2015-017-1.yaml"},{"type":"PACKAGE","url":"https://github.com/silverstripe-archive/silverstripe-forum"},{"type":"WEB","url":"https://www.silverstripe.org/software/download/security-releases/ss-2015-017"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-11-28T05:41:04.292453Z"}}