漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Statamic CMS missing authorization on Control Panel fieldtype endpoints allows disclosure of restricted resources
Vulnerability Description
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.23 and 6.20.0, an authenticated Control Panel user could view metadata and content for resources they don't have permission to view, including entries, assets, users, roles, groups, and other configured resources. Depending on the resource, this could expose titles, custom field values, entry content, asset metadata, and the existence of users, roles, and groups. No data could be modified. This has been fixed in 5.73.23 and 6.20.0.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
信息暴露
Vulnerability Title
Statamic cms 信息泄露漏洞
Vulnerability Description
Statamic cms是Statamic的内容管理系统。 Statamic cms 5.73.23之前版本和6.0.0版本至6.20.0之前版本存在安全漏洞,该漏洞源于权限验证不足,可能导致已认证的控制面板用户查看未授权资源的元数据和内容,包括条目、资产、用户、角色、组等。
CVSS Information
N/A
Vulnerability Type
N/A