CVE-2017-11422CVE-2017-11422

Affected configuration(s):

cpe:/a:statamic:framework_cms:2.5.11

Date published: 2017-07-24T08:29:00.173-04:00

Date last modified: 2017-08-10T11:39:32.157-04:00

CVSS Score: 6.5

Principal attack vector: NETWORK

Complexity:  LOW

Reference URL: https://gist.github.com/rambo691/3714c8c09cf894d574d37c294711c49e

Summary: Statamic framework before 2.6.0 does not correctly check a session’s permissions when the methods from a user’s class are called. Problematic methods include reset password, create new account, create new role, etc.

CategoriesUncategorised

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.