Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-72hg-5wr5-rmfc

Опубликовано: 12 нояб. 2023
Источник: github
Github: Прошло ревью
CVSS3: 8.3

Описание

Statamic CMS remote code execution via front-end form uploads

Impact

On front-end forms with an asset upload field, PHP files crafted to look like images may be uploaded regardless of mime validation rules. This only affects forms using the "Forms" feature and not just any arbitrary form. This does not affect the control panel.

Patches

It has been patched in 3.4.13 and 4.33.0.

Пакеты

Наименование

statamic/cms

composer
Затронутые версииВерсия исправления

>= 4.0.0, < 4.33.0

4.33.0

Наименование

statamic/cms

composer
Затронутые версииВерсия исправления

< 3.4.13

3.4.13

EPSS

Процентиль: 89%
0.04856
Низкий

8.3 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 8.3
nvd
около 2 лет назад

Statmic is a core Laravel content management system Composer package. Prior to versions 3.4.13 and 4.33.0, on front-end forms with an asset upload field, PHP files crafted to look like images may be uploaded. This only affects forms using the "Forms" feature and not just _any_ arbitrary form. This does not affect the control panel. This issue has been patched in 3.4.13 and 4.33.0.

EPSS

Процентиль: 89%
0.04856
Низкий

8.3 High

CVSS3

Дефекты

CWE-434