CVE-2018-19598: XSS
Published Dec 19, 2018
·Updated
Statamic 2.10.3 allows XSS via First Name or Last Name to the /users URI in an 'Add new user' request.
Affected Software
1 affected component
Statamic Statamic=2.10.3
Event History
Dec 19, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2018-19598.
2
What is the severity of CVE-2018-19598?
The severity of CVE-2018-19598 is medium (4.8).
3
How does CVE-2018-19598 occur?
CVE-2018-19598 occurs when an attacker is able to inject a malicious script by exploiting the 'Add new user' request in Statamic 2.10.3.
4
What is the affected software version of CVE-2018-19598?
The affected software version of CVE-2018-19598 is Statamic 2.10.3.
5
How can I fix CVE-2018-19598?
To fix CVE-2018-19598, it is recommended to upgrade to a patched version of Statamic that addresses the XSS vulnerability.