Authentication mechanism absence or evasion In statamic/cms
Description
Statamic: Account takeover via OAuth email matching without email-verification check
Impact
When OAuth login is enabled with a provider that does not guarantee verified email addresses, an unauthenticated attacker could sign in as an existing user — potentially including a super admin — without their password. Exploitation requires OAuth to be explicitly enabled with such a provider.
Patches
Fixed in 5.74.1 and 6.24.0.
Workarounds
Only enable OAuth with providers that guarantee verified email addresses, or disable OAuth login.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
packagist | 5.74.1, 6.24.0 |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3. 4. 5.