Cross-Site Request Forgery Vulnerability in SilverStripe CMS
CVE-2019-12437
8.8HIGH
What is CVE-2019-12437?
In SilverStripe versions up to 4.3.3, an incomplete fix from a previous security issue allows for Cross-Site Request Forgery attacks specifically in GraphQL mutations. This creates potential for unauthorized commands to be transmitted from users without their consent, posing a security risk to web applications built on the SilverStripe framework.
