Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Statamic framework before 2.6.0 does not correctly check a session's permissions when the methods from a user's class are called. Problematic methods include reset password, create new account, create new role, etc.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Statamic framework 访问控制错误漏洞
Vulnerability Description
Statamic framework是一个快速开发框架。该框架能具有快速创建网站页面、创建并管理网站表单等功能。 Statamic framework 2.6.0之前的中存在访问控制错误漏洞,该漏洞源于程序没有正确的检测会话权限。远程攻击者可利用该漏洞重置账户密码。
CVSS Information
N/A
Vulnerability Type
N/A