Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-64664

Опубликовано: 06 авг. 2026
Источник: nvd
CVSS3: 4.3
EPSS Низкий

Описание

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Control Panel user could use an endpoint intended for the user creation wizard to determine if a given email address belonged to an existing user, without having permission to view users, though the endpoint only exposed user existence and not any other user data. This issue is fixed in versions 5.74.1 and 6.24.0.

EPSS

Процентиль: 16%
0.00251
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 4.3
github
3 дня назад

Statamic: Missing authorization on Control Panel endpoint allows disclosure of user existence

EPSS

Процентиль: 16%
0.00251
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-200