CVE Vulnerabilities

CVE-2010-5080

Published: Aug 26, 2012 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The Security/changepassword URL action in SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 passes a token as a GET parameter while changing a password through email, which allows remote attackers to obtain sensitive data and hijack the session via the HTTP referer logs on a server, aka HTTP referer leakage.

Affected Software

Name Vendor Start Version End Version
Silverstripe Silverstripe 2.3.0 (including) 2.3.0 (including)
Silverstripe Silverstripe 2.3.0-rc1 (including) 2.3.0-rc1 (including)
Silverstripe Silverstripe 2.3.0-rc2 (including) 2.3.0-rc2 (including)
Silverstripe Silverstripe 2.3.0-rc3 (including) 2.3.0-rc3 (including)
Silverstripe Silverstripe 2.3.1 (including) 2.3.1 (including)
Silverstripe Silverstripe 2.3.1-rc1 (including) 2.3.1-rc1 (including)
Silverstripe Silverstripe 2.3.1-rc2 (including) 2.3.1-rc2 (including)
Silverstripe Silverstripe 2.3.2 (including) 2.3.2 (including)
Silverstripe Silverstripe 2.3.3 (including) 2.3.3 (including)
Silverstripe Silverstripe 2.3.4 (including) 2.3.4 (including)
Silverstripe Silverstripe 2.3.5 (including) 2.3.5 (including)
Silverstripe Silverstripe 2.3.6 (including) 2.3.6 (including)
Silverstripe Silverstripe 2.3.7 (including) 2.3.7 (including)
Silverstripe Silverstripe 2.3.8 (including) 2.3.8 (including)
Silverstripe Silverstripe 2.3.9 (including) 2.3.9 (including)
Silverstripe Silverstripe 2.4.0 (including) 2.4.0 (including)
Silverstripe Silverstripe 2.4.1 (including) 2.4.1 (including)
Silverstripe Silverstripe 2.4.2 (including) 2.4.2 (including)
Silverstripe Silverstripe 2.4.3 (including) 2.4.3 (including)

References