
Cloud Vulnerability DB
A community-led vulnerabilities database
A CSRF (Cross-Site Request Forgery) vulnerability was identified in the GridFieldAddExistingAutocompleter component of Silverstripe Framework, tracked as SS-2016-002. The vulnerability was discovered in February 2016 and affected versions 3.1.16, 3.2.1, 3.3.0-rc2 and below. The issue was patched in versions 3.1.17, 3.2.2, and 3.3.0 (Silverstripe Security).
The vulnerability stemmed from insufficient CSRF protection in the GridField component, specifically in the gridFieldAlterAction submissions which lacked proper SecurityID token validation. The vulnerability has a CVSS score of 3.6, indicating moderate severity. The issue affects the CMS interface where GridField is used for managing groups, users, and permissions (Silverstripe Security, GitHub Advisory).
Users with CMS access could be tricked into posting unspecified data into the CMS from external websites. This was particularly concerning as GridField is used for critical administrative functions including the management of groups, users, and permissions in the CMS (Silverstripe Security).
The vulnerability requires user interaction and network access to exploit. An attacker would need to trick a user with CMS access into performing specific actions from an external website. The attack complexity is considered low, but privileges are required for successful exploitation (GitHub Advisory).
The vulnerability was fixed by implementing proper CSRF protection through SecurityID token validation for all gridFieldAlterAction submissions. Users are advised to upgrade to the patched versions: 3.1.17, 3.2.2, or 3.3.0 (Silverstripe Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."