Логотип exploitDog
bind:CVE-2024-36119
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-36119

Количество 2

Количество 2

nvd логотип

CVE-2024-36119

больше 1 года назад

Statamic is a, Laravel + Git powered CMS designed for building websites. In affected versions users registering via the `user:register_form` tag will have their password confirmation stored in plain text in their user file. This only affects sites matching **all** of the following conditions: 1. Running Statamic versions between 5.3.0 and 5.6.1. (This version range represents only one calendar week), 2. Using the `user:register_form` tag. 3. Using file-based user accounts. (Does not affect users stored in a database.), 4. Has users that have registered during that time period. (Existing users are not affected.). Additionally passwords are only visible to users that have access to read user yaml files, typically developers of the application itself. This issue has been patched in version 5.6.2, however any users registered during that time period and using the affected version range will still have the the `password_confirmation` value in their yaml files. We recommend that affected use

CVSS3: 1.8
EPSS: Низкий
github логотип

GHSA-qvpj-w7xj-r6w9

больше 1 года назад

Password confirmation stored in plain text via registration form in statamic/cms

CVSS3: 1.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-36119

Statamic is a, Laravel + Git powered CMS designed for building websites. In affected versions users registering via the `user:register_form` tag will have their password confirmation stored in plain text in their user file. This only affects sites matching **all** of the following conditions: 1. Running Statamic versions between 5.3.0 and 5.6.1. (This version range represents only one calendar week), 2. Using the `user:register_form` tag. 3. Using file-based user accounts. (Does not affect users stored in a database.), 4. Has users that have registered during that time period. (Existing users are not affected.). Additionally passwords are only visible to users that have access to read user yaml files, typically developers of the application itself. This issue has been patched in version 5.6.2, however any users registered during that time period and using the affected version range will still have the the `password_confirmation` value in their yaml files. We recommend that affected use

CVSS3: 1.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-qvpj-w7xj-r6w9

Password confirmation stored in plain text via registration form in statamic/cms

CVSS3: 1.8
0%
Низкий
больше 1 года назад

Уязвимостей на страницу