Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-225x-3jhx-wh4q

Опубликовано: 06 авг. 2026
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Statamic: Missing authorization on Control Panel endpoint allows disclosure of user existence

Impact

An authenticated Control Panel user could use an endpoint intended for the user creation wizard to determine if a given email address belongs to an existing user, without having permission to view users.

The endpoint only exposed user existence, not any of its data.

Patches

This has been fixed in 5.74.1 and 6.24.0.

Пакеты

Наименование

statamic/cms

composer
Затронутые версииВерсия исправления

< 5.74.1

5.74.1

Наименование

statamic/cms

composer
Затронутые версииВерсия исправления

>= 6.0.0, < 6.24.0

6.24.0

EPSS

Процентиль: 17%
0.00251
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-200
CWE-862

Связанные уязвимости

CVSS3: 4.3
nvd
около 2 месяцев назад

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Control Panel user could use an endpoint intended for the user creation wizard to determine if a given email address belonged to an existing user, without having permission to view users, though the endpoint only exposed user existence and not any other user data. This issue is fixed in versions 5.74.1 and 6.24.0.

EPSS

Процентиль: 17%
0.00251
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-200
CWE-862