First published: Wed Dec 19 2018(Updated: )
Statamic 2.10.3 allows XSS via First Name or Last Name to the /users URI in an 'Add new user' request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Statamic Statamic | =2.10.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-19598.
The severity of CVE-2018-19598 is medium (4.8).
CVE-2018-19598 occurs when an attacker is able to inject a malicious script by exploiting the 'Add new user' request in Statamic 2.10.3.
The affected software version of CVE-2018-19598 is Statamic 2.10.3.
To fix CVE-2018-19598, it is recommended to upgrade to a patched version of Statamic that addresses the XSS vulnerability.