Skip to content

Session fixation in change password form

Moderate severity GitHub Reviewed Published Nov 12, 2019 to the GitHub Advisory Database • Updated Feb 7, 2024

Package

composer silverstripe/framework (Composer)

Affected versions

>= 3.7.0, < 3.7.4
>= 4.4.0, < 4.4.4
>= 3.6.0, < 3.6.8
>= 4.0.0, < 4.3.5

Patched versions

3.7.4
4.4.4
3.6.8
4.3.5
Reviewed Nov 12, 2019
Published to the GitHub Advisory Database Nov 12, 2019
Last updated Feb 7, 2024

Severity

Moderate
6.3
/ 10

CVSS base metrics

Attack vector
Physical
Attack complexity
High
Privileges required
None
User interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses

CVE ID

CVE-2019-12203

GHSA ID

GHSA-w7r7-r8r9-vrg2

Source code

No known source code
Checking history
See something to contribute? Suggest improvements for this vulnerability.