漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Statamic: Missing authorization on Control Panel endpoint allows disclosure of user existence
Vulnerability Description
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Control Panel user could use an endpoint intended for the user creation wizard to determine if a given email address belonged to an existing user, without having permission to view users, though the endpoint only exposed user existence and not any other user data. This issue is fixed in versions 5.74.1 and 6.24.0.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
信息暴露
Vulnerability Title
Statamic CMS 信息泄露漏洞
Vulnerability Description
Statamic cms是美国Statamic公司的一个内容管理系统。 Statamic CMS 5.74.1之前版本和6.24.0之前版本存在安全漏洞,该漏洞源于访问控制不当,可能导致已认证的控制面板用户通过用于创建用户的端点判断给定邮箱地址是否属于现有用户。
CVSS Information
N/A
Vulnerability Type
N/A