QID 996020

Date Published: 2023-11-23

QID 996020: PHP (Composer) Security Update for statamic/cms (GHSA-8jjh-j3c2-cjcv)

HTML files crafted to look like images may be uploaded regardless of mime validation. This is only applicable on front-end forms using the "Forms" feature containing an assets field, or within the control panel which requires authentication.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-8jjh-j3c2-cjcv for updates and patch information.
    Vendor References

    CVEs related to QID 996020

    Software Advisories
    Advisory ID Software Component Link
    GHSA-8jjh-j3c2-cjcv statamic/cms URL Logo github.com/advisories/GHSA-8jjh-j3c2-cjcv