Description
security/MemberLoginForm.php in SilverStripe 3.0.3 supports login using a GET request, which makes it easier for remote attackers to conduct phishing attacks without detection by the victim.
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by Fara Rustein · textwebappsphp
https://www.exploit-db.com/exploits/38689
References (2)
Core 2
Core References
Patch x_refsource_confirm
https://github.com/chillu/silverstripe-framework/commit/3e88c98ca513880e2b43ed7f27ade17fef5d9170
Exploit mailing-list
x_refsource_bugtraq
http://seclists.org/bugtraq/2013/Aug/12
Scores
EPSS
0.0575
EPSS Percentile
90.5%
Details
CWE
CWE-20
Status
published
Products (1)
silverstripe/silverstripe
3.0.3
Published
Nov 13, 2013
Tracked Since
Feb 18, 2026