A vulnerability has been found in the SilverStripe framework where a login url can be potentially redirected to an external site.
For example, the url http://www.my-silverstripe-site.com/Security/login?BackURL=/\attacker-site.com will redirect successful logins to the page http://attacker-site.com. If that website were set up to look identical to the first with "login failed" then the user will likely just enter their user/pass again.
{
    "nvd_published_at": null,
    "severity": "MODERATE",
    "github_reviewed_at": "2024-05-23T17:12:13Z",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-601"
    ]
}