CVE Vulnerabilities

CVE-2010-5078

Published: Sep 17, 2012 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain version information via a direct request to (1) apphire/silverstripe_version or (2) cms/silverstripe_version.

Affected Software

NameVendorStart VersionEnd Version
SilverstripeSilverstripe2.3.0 (including)2.3.0 (including)
SilverstripeSilverstripe2.3.1 (including)2.3.1 (including)
SilverstripeSilverstripe2.3.2 (including)2.3.2 (including)
SilverstripeSilverstripe2.3.3 (including)2.3.3 (including)
SilverstripeSilverstripe2.3.4 (including)2.3.4 (including)
SilverstripeSilverstripe2.3.5 (including)2.3.5 (including)
SilverstripeSilverstripe2.3.6 (including)2.3.6 (including)
SilverstripeSilverstripe2.3.7 (including)2.3.7 (including)
SilverstripeSilverstripe2.3.8 (including)2.3.8 (including)
SilverstripeSilverstripe2.3.9 (including)2.3.9 (including)

References