First published: Tue Sep 24 2019(Updated: )
CVE-2019-12204: Missing warning on install.php on public webroot can lead to unauthenticated admin access
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/silverstripe/framework | >=4.1.0<4.3.5>=4.4.0<4.4.4 | |
Silverstripe silverstripe | >=4.1.0<=4.3.3 | |
composer/silverstripe/framework | >=4.1.0<4.3.5 | 4.3.5 |
composer/silverstripe/cms | >=4.4.0<4.4.4 | 4.4.4 |
>=4.1.0<=4.3.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-12204 is a vulnerability that allows unauthenticated users to gain admin access through the install.php file located in the public webroot.
The CVE-2019-12204 vulnerability affects SilverStripe framework versions 4.1.0 to 4.3.5 and 4.4.0 to 4.4.4.
An attacker can exploit CVE-2019-12204 by accessing the install.php file in the public webroot and gaining unauthenticated admin access.
Yes, to fix CVE-2019-12204, update your SilverStripe framework to a version that is not affected by this vulnerability.
You can find more information about CVE-2019-12204 on the SilverStripe website at https://www.silverstripe.org/download/security-releases/cve-2019-12204/