Vulnerability DatabaseGHSA-g84q-cq55-xwgp

GHSA-g84q-cq55-xwgp
PHP vulnerability analysis and mitigation

Overview

The vulnerability (GHSA-g84q-cq55-xwgp) is a member disclosure vulnerability in the Silverstripe Framework's login form, discovered and patched in May 2017. This security issue affects versions >= 3.4.0-rc1, < 3.4.6 and >= 3.5.0-rc1, < 3.5.4 of the silverstripe/framework package. The vulnerability was fixed in versions 3.4.6 and 3.5.4 (GitHub Advisory, Silverstripe Advisory).

Technical details

The vulnerability is a user ID enumeration flaw in the brute force protection mechanism of the login system. The system behaved differently for existing versus non-existing users during login attempts, where users that didn't exist would never receive a lockout message, while existing users would get locked out after multiple failed attempts. This inconsistency in behavior created an information disclosure vector. The vulnerability has been assigned a CVSS v3.1 score of 5.3 (Moderate), with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N (GitHub Advisory).

Impact

The vulnerability allows attackers to infer or confirm the existence of user accounts in the member table through the different responses received during login attempts. This information disclosure could be used as part of a larger attack strategy, such as targeted brute force attacks against confirmed existing accounts (Silverstripe Advisory).

Exploitability

The vulnerability is exploitable remotely without requiring any privileges or user interaction. An attacker can simply attempt to login with different usernames and observe the system's responses to determine which accounts exist in the system (GitHub Advisory).

Mitigation and workarounds

The issue has been resolved by ensuring that login attempt logging and lockout processes work equivalently for both existing and non-existent users. Users should upgrade to the patched versions: 3.4.6 or 3.5.4. The fix ensures that the lockout mechanism treats all login attempts consistently, regardless of whether the user exists in the database or not (GitHub Advisory, Silverstripe Advisory).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-8cfw-pcwh-v63wHIGH8.4
  • PHP logoPHP
  • winter/wn-system-module
NoYesAug 20, 2026
GHSA-p2ch-c2c3-4xm5MEDIUM6.1
  • PHP logoPHP
  • winter/wn-backend-module
NoYesAug 20, 2026
GHSA-fm29-4mq3-phg6MEDIUM5.3
  • PHP logoPHP
  • winter/wn-backend-module
NoYesAug 20, 2026
GHSA-hq84-x37p-j6q5MEDIUM4.5
  • PHP logoPHP
  • winter/wn-backend-module
NoYesAug 20, 2026
GHSA-mpmw-f6h6-3g26MEDIUM4.3
  • PHP logoPHP
  • winter/wn-backend-module
NoYesAug 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management