PT-2022-12333 · Statamic · Statamic
Published
2022-02-10
·
Updated
2024-08-04
·
CVE-2021-45364
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Statamic versions through 3.2.26
Description
A Code Execution issue exists via SettingsController.php. However, the vendor indicates that there was an error in publishing this record, and all parties agree that the affected code was not used in any Statamic product.
Recommendations
For versions through 3.2.26, consider this issue as a false positive based on the vendor's statement that the affected code was not used in any Statamic product. At the moment, there is no information about a newer version that contains a fix for this vulnerability, but given the vendor's clarification, no action may be required.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Statamic