In SilverStripe through 4.3.3, a missing warning about leaving install.php in a public webroot can lead to unauthenticated admin access.
https://github.com/advisories/GHSA-cg8j-8w52-735v
https://www.silverstripe.org/download/security-releases/CVE-2019-12204