Description
Statmic is a core Laravel content management system Composer package. Prior to versions 3.4.13 and 4.33.0, on front-end forms with an asset upload field, PHP files crafted to look like images may be uploaded. This only affects forms using the "Forms" feature and not just _any_ arbitrary form. This does not affect the control panel. This issue has been patched in 3.4.13 and 4.33.0.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2902 | Statmic is a core Laravel content management system Composer package. Prior to versions 3.4.13 and 4.33.0, on front-end forms with an asset upload field, PHP files crafted to look like images may be uploaded. This only affects forms using the "Forms" feature and not just _any_ arbitrary form. This does not affect the control panel. This issue has been patched in 3.4.13 and 4.33.0. |
Github GHSA |
GHSA-72hg-5wr5-rmfc | Statamic CMS remote code execution via front-end form uploads |
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-09-03T17:24:55.886Z
Reserved: 2023-10-30T19:57:51.677Z
Link: CVE-2023-47129
Updated: 2024-08-02T21:01:22.814Z
Status : Modified
Published: 2023-11-10T19:15:16.617
Modified: 2024-11-21T08:29:50.363
Link: CVE-2023-47129
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA