CVE-2019-12203

MEDIUM

SilverStripe <4.3.3 - Info Disclosure

Title source: llm
STIX 2.1

Description

SilverStripe through 4.3.3 allows session fixation in the "change password" form.

References (3)

Core 3
Core References
Release Notes, Vendor Advisory x_refsource_misc
https://forum.silverstripe.org/c/releases

Scores

CVSS v3 6.3
EPSS 0.0038
EPSS Percentile 29.6%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-384
Status published
Products (2)
silverstripe/framework 3.7.0 - 3.7.4Packagist
silverstripe/silverstripe < 4.3.3
Published Sep 25, 2019
Tracked Since Feb 18, 2026