Description
SilverStripe through 4.3.3 has incorrect access control for protected files uploaded via Upload::loadIntoFile(). An attacker may be able to guess a filename in silverstripe/assets via the AssetControlExtension.
Remediation
References
Related Vulnerabilities
WordPress Plugin Unconfirmed Cross-Site Scripting (1.2.3)
WordPress Plugin Easy Contact Forms Export 'file' Parameter Information Disclosure (1.1.0)
WordPress Plugin Coming Soon/Maintenance mode Ready! Cross-Site Request Forgery (0.5.0)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-2246)