Information Exposure

Affecting silverstripe/framework package, versions >=4.0.0, <4.0.4 || >=4.1.0, <4.1.1

Report new vulnerabilities
Do your applications use this vulnerable package? Test your applications

Overview

silverstripe/framework is a PHP framework forming the base for the SilverStripe CMS.

Affected versions of this package are vulnerable to Information Exposure. The URL parameters isDev and isTest are accessible to unauthenticated users who access a SilverStripe website or application. This allows unauthorised users to expose information that is usually hidden on production environments such as verbose errors (including backtraces) and other debugging tools only available to sites running in "dev mode". Core functionality does not expose user data through these methods. Depending on your website configuration, community modules might have added more specific functionality which can be used to either access or alter user data.

Remediation

Upgrade silverstripe/framework to version 4.0.4, 4.1.1 or higher.

References

CVSS Score

5.3
medium severity
  • Attack Vector
    Network
  • Attack Complexity
    Low
  • Privileges Required
    None
  • User Interaction
    None
  • Scope
    Unchanged
  • Confidentiality
    Low
  • Integrity
    None
  • Availability
    None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Credit
Will Barker
CWE
CWE-200
Snyk ID
SNYK-PHP-SILVERSTRIPEFRAMEWORK-546500
Disclosed
05 Feb, 2020
Published
05 Feb, 2020