PT-2022-12333 · Statamic · Statamic

Published

2022-02-10

·

Updated

2024-08-04

·

CVE-2021-45364

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Statamic versions through 3.2.26
Description A Code Execution issue exists via SettingsController.php. However, the vendor indicates that there was an error in publishing this record, and all parties agree that the affected code was not used in any Statamic product.
Recommendations For versions through 3.2.26, consider this issue as a false positive based on the vendor's statement that the affected code was not used in any Statamic product. At the moment, there is no information about a newer version that contains a fix for this vulnerability, but given the vendor's clarification, no action may be required.

Exploit

Fix

Related Identifiers

CVE-2021-45364

Affected Products

Statamic