First published: Wed Jun 24 2015(Updated: )
Open redirect vulnerability in SilverStripe CMS & Framework 3.1.13 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the returnURL parameter to dev/build.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Silverstripe silverstripe | =3.1.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-5062 has a medium severity rating due to its potential to facilitate phishing attacks.
To fix CVE-2015-5062, update SilverStripe to a version later than 3.1.13 that addresses this vulnerability.
CVE-2015-5062 specifically affects SilverStripe CMS & Framework version 3.1.13.
CVE-2015-5062 can allow attackers to redirect users to malicious web sites, enabling phishing attacks.
Yes, CVE-2015-5062 can be easily exploited by manipulating the returnURL parameter.