Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2497-6pwj-pwg7

Опубликовано: 26 июн. 2026
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Statamic CMS: Missing authorization on Control Panel fieldtype endpoints allows disclosure of restricted resources

Impact

An authenticated Control Panel user could view metadata and content for resources they don't have permission to view, including entries, assets, users, roles, groups, and other configured resources. Depending on the resource, this could expose titles, custom field values, entry content, asset metadata, and the existence of users, roles, and groups. No data could be modified.

Patches

This has been fixed in 5.73.23 and 6.20.0.

Пакеты

Наименование

statamic/cms

composer
Затронутые версииВерсия исправления

< 5.73.23

5.73.23

Наименование

statamic/cms

composer
Затронутые версииВерсия исправления

>= 6.0.0, < 6.20.0

6.20.0

EPSS

Процентиль: 6%
0.00162
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-200
CWE-862
CWE-863

Связанные уязвимости

CVSS3: 4.3
nvd
около 1 месяца назад

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.23 and 6.20.0, an authenticated Control Panel user could view metadata and content for resources they don't have permission to view, including entries, assets, users, roles, groups, and other configured resources. Depending on the resource, this could expose titles, custom field values, entry content, asset metadata, and the existence of users, roles, and groups. No data could be modified. This has been fixed in 5.73.23 and 6.20.0.

EPSS

Процентиль: 6%
0.00162
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-200
CWE-862
CWE-863