Statamic framework before 2.6.0 does not correctly check a session's permissions when the methods from a user's class are called. Problematic methods include reset password, create new account, create new role, etc.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-2617 Statamic framework before 2.6.0 does not correctly check a session's permissions when the methods from a user's class are called. Problematic methods include reset password, create new account, create new role, etc.
Github GHSA Github GHSA GHSA-5m64-9hq5-5pf2 Statamic framework Incorrect Permission Assignment
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T18:12:39.441Z

Reserved: 2017-07-18T00:00:00

Link: CVE-2017-11422

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2017-07-24T12:29:00.173

Modified: 2025-04-20T01:37:25.860

Link: CVE-2017-11422

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses