SilverStripe(R) Information Exposure Through Query Strings in GET Request (C=
WE-598)
- CVE: CVE-2013-2653
- CWE: CWE-598
- Deloitte Argentina Advisory Code: DTTAR-20130002
- Vendor Status: CONFIRMED
- Vendor Disclosure Date: May, 8th, 2013.
- Public Disclosure Date: August, 1st, 2013.
- Vendors Affected: SilverStripe - http://www.silverstripe.org/
- Systems Affected: SilverStripe CMS v3.0.3
- Description: It was observed that the SilverStripe CMS application is susc=
eptible to information exposure through query strings in forced GET requests=
=2E The objective for a malicious user would be to send a specially crafted =
URL to a valid user, in an attempt to trick them into clicking this maliciou=
s link and execute the action in the victim=E2=80=99s context. A malicious u=
ser may craft a website requesting email and password, where inside an ifram=
e an automatic login to the real website could be executed and go by unnotic=
ed.
- PoC: http://<IP:Port>/Security/LoginForm?AuthenticationMethod=3DMemberA=
uthenticator&Email=3D<email>&Password=3D<password>&BackURL=3D%2Fadmin%2Fpage=
s&action_dologin=3DLog+in
NOTE: A single click to the URL above, allows access to the =
admin section of SilverStripe, redirecting the user to http://<IP:Port>/admi=
n/pages
- Vulnerability Status: in process of being released.
- Patch Available: https://github.com/chillu/silverstripe-framework/commit/3=
e88c98ca513880e2b43ed7f27ade17fef5d9170
- Fix: Will be available on 3.1 release.
- Related Links: Deloitte Argentina - www.deloitte.com/ar
- Credits: This vulnerability was found by Fara Rustein from Deloitte Argent=
ina (https://twitter.com/FaraRustein).
- Feedback: If you have any questions, comments, concerns, updates or sugges=
tions please feel free to send them to: frustein@deloitte.com
Fara Rustein
Senior Consultant, Cyber Security - ERS
Deloitte & Co. S.A.
Tte. Gral.J.D.Per=C3=B3n 646 - C1038AAN=C2=A0Buenos Aires Argentina
Main: +54 11 4320 2700 ext. 8350 | Fax: +54 11 4320 4071
frustein@deloitte.com | www.deloitte.com
=EF=81=90 Please consider the environment before printing.
=C2=A0
Deloitte se refiere a una o m=C3=A1s de las firmas miembros de Deloitte Touc=
he Tohmatsu Limited, una compa=C3=B1=C3=ADa privada del Reino Unido limitada=
por garant=C3=ADa, y su red de firmas miembros, cada una como una entidad =
=C3=BAnica e independiente y legalmente separada.=C2=A0Una descripci=C3=B3n =
detallada de la estructura legal de Deloitte Touche Tohmatsu Limited y sus f=
irmas miembros puede verse en el sitio web http://www.deloitte.com/about.=
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=
=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=
=C2=A0=C2=A0La informaci=C3=B3n de este mail es confidencial y concierne =
=C3=BAnicamente a la persona a quien est=C3=A1 dirigida. Si este mensaje no =
est=C3=A1 dirigido a usted, por favor tenga presente que no tiene autorizaci=
=C3=B3n para leer el resto de este e-mail, copiarlo o derivarlo a cualquier =
otra persona que no sea aquella a quien est=C3=A1 dirigido. Si recibe este m=
ail por error, por favor, avise al remitente, luego de lo cual rogamos a ust=
ed destruya el mensaje original. No se puede responsabilizar de ning=C3=BAn =
modo a Deloitte & Co. S.A. ni a sus subsidiarias por cualquier consecuencia =
o da=C3=B1o que pueda resultar del apropiado y completo env=C3=ADo y recepci=
=C3=B3n del contenido de este e-mail.
=C2=A0
Deloitte refers to one or more of Deloitte Touche Tohmatsu Limited, a UK pri=
vate company limited by guarantee, and its network of member firms, each of =
which is a legally separate and independent entity. Please see=C2=A0http://w=
ww.deloitte.com/about=C2=A0for a detailed description of the legal structure=
of Deloitte Touche Tohmatsu Limited and its member firms.=C2=A0
The information in this e-mail is confidential and intended solely for the p=
erson to whom it is addressed. If this message is not addressed to you, plea=
se be aware that you have no authorization to read the rest of this e-mail, =
to copy it or to furnish it to any person other than the addressee. Should y=
ou have received this e-mail by mistake, please bring this to the attention =
of the sender, after which you are kindly requested to destroy the original =
message.=C2=A0Deloitte & Co. S.A. and subsidiaries cannot be held responsibl=
e or liable in any way whatsoever for and/or in connection with any conseque=
nces and/or damage resulting from the proper and complete dispatch and recei=
pt of the content of this e-mail.