silverstripe/framework BackURL validation bypass with malformed URLs
High severity
GitHub Reviewed
Published
May 27, 2024
to the GitHub Advisory Database
•
Updated May 27, 2024
Package
Affected versions
>= 4.0.0-rc1, < 4.0.4
>= 4.1.0-rc1, < 4.1.1
Patched versions
4.0.4
4.1.1
Description
Published to the GitHub Advisory Database
May 27, 2024
Reviewed
May 27, 2024
Last updated
May 27, 2024
A carefully constructed malformed URL can be used to circumvent the offsite redirection protection used on
BackURL
parameters. This could lead to users entering sensitive data in malicious websites instead of the intended one.References