Description
Statmatic is a Laravel and Git powered content management system (CMS). Prior to version 5.17.0, assets uploaded with appropriately crafted filenames may result in them being placed in a location different than what was configured. The issue affects front-end forms with `assets` fields and other places where assets can be uploaded, although users would need upload permissions anyway. Files can be uploaded so they would be located on the server in a different location, and potentially override existing files. Traversal outside an asset container is not possible. This path traversal vulnerability has been fixed in 5.17.0.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-3371 | Statmatic is a Laravel and Git powered content management system (CMS). Prior to version 5.17.0, assets uploaded with appropriately crafted filenames may result in them being placed in a location different than what was configured. The issue affects front-end forms with `assets` fields and other places where assets can be uploaded, although users would need upload permissions anyway. Files can be uploaded so they would be located on the server in a different location, and potentially override existing files. Traversal outside an asset container is not possible. This path traversal vulnerability has been fixed in 5.17.0. |
Github GHSA |
GHSA-p7f6-8mcm-fwv3 | Statamic CMS has a Path Traversal in Asset Upload |
References
History
Tue, 03 Dec 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Statamic
Statamic statamic |
|
| CPEs | cpe:2.3:a:statamic:statamic:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Statamic
Statamic statamic |
|
| Metrics |
ssvc
|
Tue, 19 Nov 2024 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Statmatic is a Laravel and Git powered content management system (CMS). Prior to version 5.17.0, assets uploaded with appropriately crafted filenames may result in them being placed in a location different than what was configured. The issue affects front-end forms with `assets` fields and other places where assets can be uploaded, although users would need upload permissions anyway. Files can be uploaded so they would be located on the server in a different location, and potentially override existing files. Traversal outside an asset container is not possible. This path traversal vulnerability has been fixed in 5.17.0. | |
| Title | Statamic CMS has Path Traversal in Asset Upload | |
| Weaknesses | CWE-22 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-12-03T17:18:17.282Z
Reserved: 2024-11-14T15:05:46.770Z
Link: CVE-2024-52600
Updated: 2024-12-03T17:18:04.997Z
Status : Deferred
Published: 2024-11-19T17:15:56.030
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-52600
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA