SilverStripe before 2.4.2 allows remote authenticated users to change administrator passwords via vectors related to admin/security.Referenceshttp://www.openwall.com/lists/oss-security/2012/05/01/3http://doc.silverstripe.org/sapphire/en/trunk/changelogs//2.4.2http://www.openwall.com/lists/oss-security/2012/04/30/1http://www.openwall.com/lists/oss-security/2012/04/30/3