Описание
Statmatic is a Laravel and Git powered content management system (CMS). Stored XSS vulnerabilities in Collections and Taxonomies allow authenticated users with content creation permissions to inject malicious JavaScript that executes when viewed by higher-privileged users. This vulnerability is fixed in 5.22.1.
EPSS
Процентиль: 14%
0.00046
Низкий
8 High
CVSS3
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 8
github
3 месяца назад
Statamic Vulnerable to Superadmin Account Takeover via Stored Cross-Site Scripting and Lack of Proper X-CSRF-TOKEN Server-Side Validation
EPSS
Процентиль: 14%
0.00046
Низкий
8 High
CVSS3
Дефекты
CWE-79