logo

Database

Remote command execution In statamic/cms

Description

Statamic: Unsafe method invocation via Antlers template resolution allows data destruction

Impact

Manipulating user-supplied input incorporated into Antlers templates could result in the loss of content and assets.

Exploitation requires a site to have templates that pass untrusted input into affected areas. It does not require authentication.

Patches

This has been fixed in 5.74.1 and 6.24.0.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions