LoginForm calls disableSecurityToken(), which causes a "shared host domain" vulnerability: http://stackoverflow.com/a/15350123.
| Software | From | Fixed in |
|---|---|---|
silverstripe / framework
|
3.1.18 | 3.1.19 |
silverstripe / framework
|
3.2.3 | 3.2.4 |
silverstripe / framework
|
3.3.1 | 3.3.2 |