CVE-2020-9322: XSS
The /users endpoint in Statamic Core before 2.11.8 allows XSS to add an administrator user. This can be exploited via CSRF. Stored XSS can occur via a JavaScript payload in a username during account registration. Reflected XSS can occur via the /users PATHINFO.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-9322?
CVE-2020-9322 has a severity that can lead to stored and reflected XSS vulnerabilities, making it critical for administrators to address.
How do I fix CVE-2020-9322?
To fix CVE-2020-9322, upgrade Statamic Core to version 2.11.8 or later.
What exploit methods are associated with CVE-2020-9322?
CVE-2020-9322 can be exploited via CSRF for adding an administrator user, with stored XSS through JavaScript payloads during account registration.
Is CVE-2020-9322 present in older versions of Statamic Core?
Yes, CVE-2020-9322 affects all versions of Statamic Core prior to 2.11.8.
What are the potential impacts of CVE-2020-9322 vulnerabilities?
The impacts include unauthorized access and manipulation of user accounts, which can lead to the compromise of sensitive information.