Vulnerability DatabaseGHSA-2hpc-mf4q-j885

GHSA-2hpc-mf4q-j885
PHP vulnerability analysis and mitigation

Overview

A CSRF (Cross-Site Request Forgery) vulnerability was identified in the GridFieldAddExistingAutocompleter component of Silverstripe Framework, tracked as SS-2016-002. The vulnerability was discovered in February 2016 and affected versions 3.1.16, 3.2.1, 3.3.0-rc2 and below. The issue was patched in versions 3.1.17, 3.2.2, and 3.3.0 (Silverstripe Security).

Technical details

The vulnerability stemmed from insufficient CSRF protection in the GridField component, specifically in the gridFieldAlterAction submissions which lacked proper SecurityID token validation. The vulnerability has a CVSS score of 3.6, indicating moderate severity. The issue affects the CMS interface where GridField is used for managing groups, users, and permissions (Silverstripe Security, GitHub Advisory).

Impact

Users with CMS access could be tricked into posting unspecified data into the CMS from external websites. This was particularly concerning as GridField is used for critical administrative functions including the management of groups, users, and permissions in the CMS (Silverstripe Security).

Exploitability

The vulnerability requires user interaction and network access to exploit. An attacker would need to trick a user with CMS access into performing specific actions from an external website. The attack complexity is considered low, but privileges are required for successful exploitation (GitHub Advisory).

Mitigation and workarounds

The vulnerability was fixed by implementing proper CSRF protection through SecurityID token validation for all gridFieldAlterAction submissions. Users are advised to upgrade to the patched versions: 3.1.17, 3.2.2, or 3.3.0 (Silverstripe Security).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-77143HIGH8.8
  • PHP logoPHP
  • composer://jweiland/pforum
NoYesAug 25, 2026
CVE-2026-77142HIGH8.8
  • PHP logoPHP
  • composer://jweiland/yellowpages2
NoYesAug 25, 2026
CVE-2026-77146HIGH8.3
  • PHP logoPHP
  • composer://in2code/femanager
NoYesAug 25, 2026
CVE-2026-77145HIGH7.1
  • PHP logoPHP
  • composer://jweiland/events2
NoYesAug 25, 2026
CVE-2026-77144HIGH7.1
  • PHP logoPHP
  • composer://jweiland/events2
NoYesAug 25, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management