Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qh8c-7588-qfrv

Опубликовано: 06 авг. 2026
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Statamic: Missing authorization on navigation endpoint allows disclosure of restricted entries

Impact

An authenticated Control Panel user could view content from entries they don't have permission to view, including entry content and custom field values, from any collection and including unpublished entries. No data could be modified.

Patches

This has been fixed in 5.74.1 and 6.24.0.

Пакеты

Наименование

statamic/cms

composer
Затронутые версииВерсия исправления

< 5.74.1

5.74.1

Наименование

statamic/cms

composer
Затронутые версииВерсия исправления

>= 6.0.0, < 6.24.0

6.24.0

EPSS

Процентиль: 23%
0.00305
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-639
CWE-862

Связанные уязвимости

CVSS3: 6.5
nvd
3 дня назад

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Control Panel user could view content from entries they did not have permission to view, including entry content and custom field values, from any collection and including unpublished entries, through the navigation endpoint, though no data could be modified. This issue is fixed in versions 5.74.1 and 6.24.0.

EPSS

Процентиль: 23%
0.00305
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-639
CWE-862