CVE-2023-22729

MEDIUM

Silverstripe Framework < 4.12.5 - Open Redirect

Title source: rule
STIX 2.1

Description

Silverstripe Framework is the Model-View-Controller framework that powers the Silverstripe content management system. Prior to version 4.12.15, an attacker can display a link to a third party website on a login screen by convincing a legitimate content author to follow a specially crafted link. Users should upgrade to Silverstripe Framework 4.12.15 or above to address the issue.

Scores

CVSS v3 5.4
EPSS 0.0020
EPSS Percentile 42.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-601
Status published
Products (2)
silverstripe/framework < 4.12.5
silverstripe/framework 0 - 4.12.5Packagist
Published Apr 26, 2023
Tracked Since Feb 18, 2026