PT-2026-25092 · Git+2 · Cms+2

Shirshaw64P

·

Publicado

2026-03-12

·

Atualizado

2026-03-14

·

CVE-2026-32612

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Statamic versions prior to 6.6.2
Description Statamic is a Laravel and Git powered content management system (CMS). A stored cross-site scripting (XSS) issue exists in the control panel color mode preference. This allows authenticated users with control panel access to inject malicious JavaScript. The injected JavaScript executes when a higher-privileged user impersonates their account. The issue allows for potential privilege escalation.
Recommendations Versions prior to 6.6.2 should be updated to version 6.6.2 or later.

Exploit

Correção

LPE

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-32612
GHSA-HCCH-W73C-JP4M

Produtos afetados

Cms
Statamic
Statamic Cms