CVE-2013-2653

Published
View on NVD ↗
CVSS v3
N/A
CVSS v2
5.8
MEDIUM
Affected
1
PROJECT

Description

security/MemberLoginForm.php in SilverStripe 3.0.3 supports login using a GET request, which makes it easier for remote attackers to conduct phishing attacks without detection by the victim.

SilverStripe's Sapphire Framework
GitHubGitHub
3