Security Advisory

CVE-2017-12849

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-10-12 15:00:00
Last updated 2024-08-05 18:51:06
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Response discrepancy in the login and password reset forms in SilverStripe CMS before 3.5.5 and 3.6.x before 3.6.1 allows remote attackers to enumerate users via timing attacks.