Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The /users endpoint in Statamic Core before 2.11.8 allows XSS to add an administrator user. This can be exploited via CSRF. Stored XSS can occur via a JavaScript payload in a username during account registration. Reflected XSS can occur via the /users PATH_INFO.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Statamic Core 安全漏洞
Vulnerability Description
Statamic Core是美国Statamic公司的一个内容管理系统的核心组件。 Statamic Core 2.11.8之前版本存在安全漏洞,该漏洞源于/users端点未正确验证输入,可能导致跨站脚本攻击。
CVSS Information
N/A
Vulnerability Type
N/A