Vulnerability DatabaseGHSA-m2hh-2m46-x6j5

GHSA-m2hh-2m46-x6j5
PHP vulnerability analysis and mitigation

Overview

A database credentials disclosure vulnerability (SS-2018-018) was identified in SilverStripe Framework versions 3.7 and 4.x. The vulnerability was discovered in 2018 and affected multiple versions including ^3.7, ^4.0, with fixes released in versions 3.7.1, 4.0.5, 4.1.3, and 4.2.2. The issue specifically impacted systems running in development mode with the mysqli database driver (Silverstripe Advisory).

Technical details

The vulnerability occurs when running SilverStripe 3.7 or 4.x in development mode with the mysqli database driver, where database connection details could potentially be exposed through stack traces during database connection failures. The issue has been assigned a moderate severity rating with a CVSS score of 6.5, indicating a significant but not critical security risk (GitHub Advisory).

Impact

The vulnerability could lead to the disclosure of sensitive database connection credentials when database errors occur in development mode. This exposure of credentials could potentially allow unauthorized access to the database if the information falls into malicious hands (GitHub Advisory).

Exploitability

The vulnerability requires the application to be running in development mode with the mysqli database driver, and a database connection failure must occur for the credentials to be exposed. The attack vector is network-based with low attack complexity and requires low privileges (GitHub Advisory).

Mitigation and workarounds

The issue has been fixed by blacklisting sensitive parts of the connection information from being included in development mode stack traces when database errors occur. Users should upgrade to the patched versions: 3.7.1, 4.0.5, 4.1.3, or 4.2.2, depending on their current version (Silverstripe Advisory).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-59989CRITICAL9.2
  • PHP logoPHP
  • phalcon/cphalcon
NoYesAug 21, 2026
CVE-2026-63135HIGH8.2
  • PHP logoPHP
  • yourls/yourls
NoYesAug 21, 2026
GHSA-p2ch-c2c3-4xm5MEDIUM6.1
  • PHP logoPHP
  • winter/wn-backend-module
NoYesAug 20, 2026
GHSA-8hgv-xc77-jmcrMEDIUM5.1
  • PHP logoPHP
  • getgrav/grav
NoYesAug 21, 2026
GHSA-hq84-x37p-j6q5MEDIUM4.5
  • PHP logoPHP
  • winter/wn-backend-module
NoYesAug 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management