Affected configuration(s):
cpe:/a:statamic:framework_cms:2.5.11
Date published: 2017-07-24T08:29:00.173-04:00
Date last modified: 2017-08-10T11:39:32.157-04:00
CVSS Score: 6.5
Principal attack vector: NETWORK
Complexity: LOW
Reference URL: https://gist.github.com/rambo691/3714c8c09cf894d574d37c294711c49e
Summary: Statamic framework before 2.6.0 does not correctly check a session’s permissions when the methods from a user’s class are called. Problematic methods include reset password, create new account, create new role, etc.