github.com
https://github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/framework/SS-2017-010-1.yaml GHSA-R3PR-FH25-WRFC
silverstripe/framework's install.php script discloses sensitive data by pre-populating DB credential forms
Description
When accessing the `install.php` script it is possible to extract any pre-configured database or default admin account password by viewing the source of the page, and inspecting the `value` property of the password fields.
Description source: GitHub Advisory
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
silverstripe/frameworkBrowse Packagist / silverstripe/framework | GitHub Advisory | 4.0.0-rc1 to < 4.0.1 · Fixed in 4.0.1 | affected |
References
4github.com
https://github.com/silverstripe/silverstripe-framework github.com
https://github.com/silverstripe/silverstripe-framework/commit/7a79cd039a96ef54182263d5fbb72addf093b171 silverstripe.org
https://www.silverstripe.org/download/security-releases/ss-2017-010