silverstripeCMS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability - CVE-2013-6789 - Vulnerability Database

silverstripeCMS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability - CVE-2013-6789

Medium
Reference: CVE-2013-6789
Title: silverstripeCMS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Overview:

security/MemberLoginForm.php in SilverStripe 3.0.3 supports credentials in a GET request which allows remote or local attackers to obtain sensitive information by reading web-server access logs web-server Referer logs or the browser history a similar vulnerability to CVE-2013-2653.