Vulnerable Systems:
* SilverStripe SilverStripe 2.4.6 and Prior
A successful exploit may aid in phishing attacks; other attacks are possible. SilverStripe could allow a remote attacker to conduct phishing attacks, caused by an open redirect vulnerability in the index.php script. A remote authenticated attacker could exploit this vulnerability using the BackURL parameter in a specially-crafted URL to redirect a victim to arbitrary Web sites.
SilverStripe CMS contains a flaw that allows a remote cross site redirection attack. This flaw exists because the application does not validate the "BackURL" parameter upon submission to the "/index.php/Security/login" script. This could allow a user to create a specially crafted URL, that if clicked, would redirect a victim from the intended legitimate web site to an arbitrary web site of the attacker's choosing.
Disclosure Timeline:
Published : Oct 15 2012
Updated : Oct 15 2012