CVE-2019-12204: Missing warning can lead to unauthenticated admin access in SilverStripe
(updated )
In SilverStripe through 4.3.3, a missing warning about leaving install.php in a public webroot can lead to unauthenticated admin access.
References
- forum.silverstripe.org/c/releases
- github.com/advisories/GHSA-cg8j-8w52-735v
- nvd.nist.gov/vuln/detail/CVE-2019-12204
- packagist.org/packages/silverstripe/cms
- packagist.org/packages/silverstripe/framework
- www.silverstripe.org/download/security-releases/
- www.silverstripe.org/download/security-releases/CVE-2019-12204
Detect and mitigate CVE-2019-12204 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →