CVE-2023-47129

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
10/11/2023
Last modified:
17/11/2023

Description

Statmic is a core Laravel content management system Composer package. Prior to versions 3.4.13 and 4.33.0, on front-end forms with an asset upload field, PHP files crafted to look like images may be uploaded. This only affects forms using the "Forms" feature and not just _any_ arbitrary form. This does not affect the control panel. This issue has been patched in 3.4.13 and 4.33.0.<br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:statamic:statamic:*:*:*:*:*:*:*:* 3.4.13 (excluding)
cpe:2.3:a:statamic:statamic:*:*:*:*:*:*:*:* 4.0.0 (including) 4.33.0 (excluding)