Statmatic is a Laravel and Git powered content management system (CMS). Prior to version 5.17.0, assets uploaded with appropriately crafted filenames may result in them being placed in a location different than what was configured. The issue affects front-end forms with `assets` fields and other places where assets can be uploaded, although users would need upload permissions anyway. Files can be uploaded so they would be located on the server in a different location, and potentially override existing files. Traversal outside an asset container is not possible. This path traversal vulnerability has been fixed in 5.17.0.
Metrics
Affected Vendors & Products
References
History
Tue, 03 Dec 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Statamic
Statamic statamic |
|
CPEs | cpe:2.3:a:statamic:statamic:*:*:*:*:*:*:*:* | |
Vendors & Products |
Statamic
Statamic statamic |
|
Metrics |
ssvc
|
Tue, 19 Nov 2024 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Statmatic is a Laravel and Git powered content management system (CMS). Prior to version 5.17.0, assets uploaded with appropriately crafted filenames may result in them being placed in a location different than what was configured. The issue affects front-end forms with `assets` fields and other places where assets can be uploaded, although users would need upload permissions anyway. Files can be uploaded so they would be located on the server in a different location, and potentially override existing files. Traversal outside an asset container is not possible. This path traversal vulnerability has been fixed in 5.17.0. | |
Title | Statamic CMS has Path Traversal in Asset Upload | |
Weaknesses | CWE-22 | |
References |
|
|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-11-19T16:30:12.221Z
Updated: 2024-12-03T17:18:17.282Z
Reserved: 2024-11-14T15:05:46.770Z
Link: CVE-2024-52600
Vulnrichment
Updated: 2024-12-03T17:18:04.997Z
NVD
Status : Awaiting Analysis
Published: 2024-11-19T17:15:56.030
Modified: 2024-11-19T21:56:45.533
Link: CVE-2024-52600
Redhat
No data.