Description

### Impact User enumeration is possible by performing a timing attack on the login or password reset pages with user credentials. This was originally disclosed in https://www.silverstripe.org/download/security-releases/ss-2017-005/ for CMS 3 but was not patched in CMS 4+ ### References - https://www.silverstripe.org/download/security-releases/ss-2017-005 - https://www.silverstripe.org/download/security-releases/ss-2025-001

Description source: GitHub Advisory

Affected products and versions

1
ProductSourceVersion rangeStatus
GitHub Advisory4.0.0 to < 5.3.23 · Fixed in 5.3.23affected

References

7