Vulnerabilities > Silverstripe > Silverstripe > 2.3.4

DATE CVE VULNERABILITY TITLE RISK
2012-08-26 CVE-2010-5080 Cross-Site Request Forgery (CSRF) vulnerability in Silverstripe
The Security/changepassword URL action in SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 passes a token as a GET parameter while changing a password through email, which allows remote attackers to obtain sensitive data and hijack the session via the HTTP referer logs on a server, aka "HTTP referer leakage."
6.8
2010-04-28 CVE-2010-1593 Cross-Site Scripting vulnerability in Silverstripe
Multiple cross-site scripting (XSS) vulnerabilities in SilverStripe before 2.3.5 allow remote attackers to inject arbitrary web script or HTML via (1) the CommenterURL parameter to PostCommentForm, and in the Forum module before 0.2.5 in SilverStripe before 2.3.5 allow remote attackers to inject arbitrary web script or HTML via (2) the Search parameter to forums/search (aka the search script).
4.3