Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j2vp-f2pv-5rj4

Опубликовано: 06 авг. 2026
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Statamic: Unsafe method invocation via Antlers template resolution allows data destruction

Impact

Manipulating user-supplied input incorporated into Antlers templates could result in the loss of content and assets.

Exploitation requires a site to have templates that pass untrusted input into affected areas. It does not require authentication.

Patches

This has been fixed in 5.74.1 and 6.24.0.

Пакеты

Наименование

statamic/cms

composer
Затронутые версииВерсия исправления

< 5.74.1

5.74.1

Наименование

statamic/cms

composer
Затронутые версииВерсия исправления

>= 6.0.0, < 6.24.0

6.24.0

EPSS

Процентиль: 22%
0.00296
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-470

Связанные уязвимости

CVSS3: 6.5
nvd
3 дня назад

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, manipulating user-supplied input incorporated into Antlers templates could result in the loss of content and assets, on sites whose templates pass untrusted input into affected areas, and exploitation did not require authentication. This issue is fixed in versions 5.74.1 and 6.24.0.

EPSS

Процентиль: 22%
0.00296
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-470