HIGH
Statamic CMS vulnerable to Cross-site Scripting via uploaded assets
Published Nov 21, 2023
7.5
HIGHCVSS 3.1
EPSS 0.70%
Description
Statamic CMS is a Laravel and Git powered content management system (CMS). Prior to versions 3.4.15 an 4.36.0, HTML files crafted to look like images may be uploaded regardless of mime validation. This is only applicable on front-end forms using the "Forms" feature containing an assets field, or within the control panel which requires authentication. This issue has been patched on 3.4.15 and 4.36.0.
Affected products
-
Affected
- < 3.4.15
- ≥ 4.0.0, < 4.36.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-2924 Advisory
- https://github.com/advisories/GHSA-8jjh-j3c2-cjcv Advisory
- https://github.com/statamic/cms/releases/tag/v3.4.15 x_refsource_MISCRelease Notes
- https://github.com/statamic/cms/releases/tag/v4.36.0 x_refsource_MISCRelease Notes
- https://github.com/statamic/cms/security/advisories/GHSA-8jjh-j3c2-cjcv x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-48701
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-2924 | Advisory | |
| https://github.com/advisories/GHSA-8jjh-j3c2-cjcv | Advisory | |
| https://github.com/statamic/cms/releases/tag/v3.4.15 | x_refsource_MISCRelease Notes | |
| https://github.com/statamic/cms/releases/tag/v4.36.0 | x_refsource_MISCRelease Notes | |
| https://github.com/statamic/cms/security/advisories/GHSA-8jjh-j3c2-cjcv | x_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2023-48701 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Nov 21, 2023
Updated Aug 2, 2024
Reserved Nov 17, 2023
Link CVE-2023-48701
CISA Vulnrichment
No data
Red Hat
No data
GitHub
Link GHSA-8JJH-J3C2-CJCV