ZeroHour

CVE-2017-12849

CVSS 3.0
5.3 medium
EPSS
1%p64
Published
()
Modified
Description

Response discrepancy in the login and password reset forms in SilverStripe CMS before 3.5.5 and 3.6.x before 3.6.1 allows remote attackers to enumerate users via timing attacks.

Vendors
silverstripe
Products
silverstripe
Weakness
CWE-200
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.