Impact
Statamic, a Laravel‑based CMS, has a flaw in the Live Preview endpoint that, before versions 5.74.0 and 6.20.3, only checks that a user has view permission while still accepting and rendering data supplied by the caller. A control‑panel user who can view but not edit content can therefore post arbitrary field values to the endpoint, creating a shareable Live Preview URL that renders the supplied content. Based on the description, it is inferred that unauthorized users could effectively submit content.
Affected Systems
Statamic CMS versions earlier than 5.74.0 and 6.20.3 are affected. Administrators using Statamic 5.x or 6.x releases prior to these patch versions should verify their current installation matches the vulnerable range.
Risk and Exploitability
The CVSS score of 3.5 reflects a moderate impact, and the EPSS score of less than 1% indicates a low likelihood of widespread exploitation at present. This vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit the bug by authenticating as any user with view rights, accessing the control panel to trigger a Live Preview request, and supplying arbitrary field values. The likely attack vector is through the normal web interface, with no need for elevated network privileges, making the weakness relatively straightforward to exploit if the system is unpatched.
OpenCVE Enrichment
Github GHSA