Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2

Количество 2

nvd логотип

CVE-2026-64664

около 2 месяцев назад

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Control Panel user could use an endpoint intended for the user creation wizard to determine if a given email address belonged to an existing user, without having permission to view users, though the endpoint only exposed user existence and not any other user data. This issue is fixed in versions 5.74.1 and 6.24.0.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-225x-3jhx-wh4q

около 2 месяцев назад

Statamic: Missing authorization on Control Panel endpoint allows disclosure of user existence

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-64664

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Control Panel user could use an endpoint intended for the user creation wizard to determine if a given email address belonged to an existing user, without having permission to view users, though the endpoint only exposed user existence and not any other user data. This issue is fixed in versions 5.74.1 and 6.24.0.

CVSS3: 4.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-225x-3jhx-wh4q

Statamic: Missing authorization on Control Panel endpoint allows disclosure of user existence

CVSS3: 4.3
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу