Silverstripe CMS information disclosure
High severity
GitHub Reviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated May 22, 2024
Description
Published by the National Vulnerability Database
Jul 15, 2020
Published to the GitHub Advisory Database
May 24, 2022
Reviewed
Jul 13, 2023
Last updated
May 22, 2024
In SilverStripe through 4.5.0, a specific URL path configured by default through the silverstripe/framework module can be used to disclose the fact that a domain is hosting a Silverstripe application. There is no disclosure of the specific version. The functionality on this URL path is limited to execution in a CLI context, and is not known to present a vulnerability through web-based access. As a side-effect, this preconfigured path also blocks the creation of other resources on this path (e.g. a page).
References