CVE-2024-52600 – statamic/cms
Package
Manager: composer
Name: statamic/cms
Vulnerable Version: >=0 <5.17.0
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
EPSS: 0.00214 pctl0.43927
Details
Statamic CMS has a Path Traversal in Asset Upload Assets uploaded with appropriately crafted filenames may result in them being placed in a location different than what was configured. ### Impact - Affects front-end forms with `assets` fields. - Affects other places where assets can be uploaded, although users would need upload permissions anyway. - Files can be uploaded so they would be located on the server in a different location, and potentially override existing files. - Traversal _outside_ an asset container was not possible. ### Patches This has been fixed in 5.17.0.
Metadata
Created: 2024-11-19T18:03:07Z
Modified: 2024-11-19T20:50:30Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/11/GHSA-p7f6-8mcm-fwv3/GHSA-p7f6-8mcm-fwv3.json
CWE IDs: ["CWE-22"]
Alternative ID: GHSA-p7f6-8mcm-fwv3
Finding: F063
Auto approve: 1