CVE-2017-11422: High severity statamic vulnerability
Published Jul 24, 2017
·Updated
Statamic framework before 2.6.0 does not correctly check a session's permissions when the methods from a user's class are called. Problematic methods include reset password, create new account, create new role, etc.
Affected Software
2 affected componentsFixes available
composer/statamic/cms<2.6.0
2.6.0
Statamic Statamic<2.6.0
Event History
Jul 24, 2017
CVE Published
via MITRE·12:00 PM
Data Sourced
via MITRE·12:00 PM
Description
May 13, 2022
Advisory Published
01:12 AM
Frequently Asked Questions
1
What is the severity of CVE-2017-11422?
CVE-2017-11422 is considered a high severity vulnerability due to potential unauthorized user actions.
2
How do I fix CVE-2017-11422?
To fix CVE-2017-11422, upgrade the Statamic framework to version 2.6.0 or later.
3
What are the implications of CVE-2017-11422?
CVE-2017-11422 allows unauthorized users to invoke sensitive methods, potentially compromising application security.
4
Who is affected by CVE-2017-11422?
CVE-2017-11422 affects all users running Statamic versions prior to 2.6.0.
5
What methods are vulnerable in CVE-2017-11422?
CVE-2017-11422 relates to vulnerable methods such as reset password, create new account, and create new role.