{"id":"GHSA-vj2j-6g3w-4662","summary":"Silverstripe Missing CSRF protection in login form","details":"LoginForm calls disableSecurityToken(), which causes a \"shared host domain\" vulnerability: http://stackoverflow.com/a/15350123.","modified":"2024-11-28T05:31:51.042310Z","published":"2024-05-23T19:41:41Z","database_specific":{"cwe_ids":["CWE-352"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-05-23T19:41:41Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/silverstripe/silverstripe-framework/commit/a6bd22ab2f3b11a054d20be13306a19089510989"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/framework/SS-2016-006-1.yaml"},{"type":"PACKAGE","url":"https://github.com/silverstripe/silverstripe-framework"},{"type":"WEB","url":"https://stackoverflow.com/questions/6412813/do-login-forms-need-tokens-against-csrf-attacks/15350123#15350123"},{"type":"WEB","url":"https://www.silverstripe.org/download/security-releases/ss-2016-006"}],"affected":[{"package":{"name":"silverstripe/framework","ecosystem":"Packagist","purl":"pkg:composer/silverstripe/framework"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.1.18"},{"fixed":"3.1.19"}]}],"versions":["3.1.18","3.1.19-rc1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-vj2j-6g3w-4662/GHSA-vj2j-6g3w-4662.json"}},{"package":{"name":"silverstripe/framework","ecosystem":"Packagist","purl":"pkg:composer/silverstripe/framework"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.2.3"},{"fixed":"3.2.4"}]}],"versions":["3.2.3","3.2.4-rc1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-vj2j-6g3w-4662/GHSA-vj2j-6g3w-4662.json"}},{"package":{"name":"silverstripe/framework","ecosystem":"Packagist","purl":"pkg:composer/silverstripe/framework"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.3.1"},{"fixed":"3.3.2"}]}],"versions":["3.3.1","3.3.2-rc1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-vj2j-6g3w-4662/GHSA-vj2j-6g3w-4662.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"}]}