First published: Sat Jan 07 2023(Updated: )
A vulnerability was found in Symbiote Seed up to 6.0.2. It has been classified as critical. Affected is the function `onBeforeSecurityLogin` of the file `code/extensions/SecurityLoginExtension.php` of the component `Login`. The manipulation of the argument URL leads to open redirect. It is possible to launch the attack remotely. Upgrading to version 6.0.3 can address this issue. The name of the patch is b065ebd82da53009d273aa7e989191f701485244. It is recommended to upgrade the affected component. VDB-217626 is the identifier assigned to this vulnerability.
Credit: cna@vuldb.com cna@vuldb.com cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/symbiote/silverstripe-seed | <6.0.3 | 6.0.3 |
Symbiote Seed | >=6.0.0<6.0.3 | |
Symbiote Seed | >=6.0.0<6.0.3 | |
>=6.0.0<6.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-20164 is medium with a severity value of 6.1.
To fix CVE-2017-20164, upgrade Symbiote Seed to version 6.0.3 or higher.
The affected software of CVE-2017-20164 is Symbiote Seed up to version 6.0.2.
The CWE ID of CVE-2017-20164 is 601.
Yes, you can find additional information about CVE-2017-20164 at the following references: [Reference 1](https://nvd.nist.gov/vuln/detail/CVE-2017-20164), [Reference 2](https://github.com/symbiote/silverstripe-seed/commit/b065ebd82da53009d273aa7e989191f701485244), [Reference 3](https://github.com/symbiote/silverstripe-seed/releases/tag/6.0.3).