CVE-2021-45364: Critical severity statamic vulnerability
Published Feb 10, 2022
·Updated
DISPUTED A Code Execution vulnerability exists in Statamic Version through 3.2.26 via SettingsController.php. NOTE: the vendor indicates that there was an error in publishing this CVE Record, and that all parties agree that the affected code was not used in any Statamic product.
Affected Software
1 affected component
Statamic Statamic<=3.2.26
Event History
Feb 10, 2022
CVE Published
via MITRE·06:38 PM
Data Sourced
via MITRE·06:38 PM
Description
Disputed
07:15 PM
Data Sourced
via NVD·07:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-45364.
2
What is the severity of CVE-2021-45364?
The severity of CVE-2021-45364 is critical with a CVSS score of 9.8.
3
What is affected by CVE-2021-45364?
Statamic Version through 3.2.26 is affected by CVE-2021-45364.
4
How can the Code Execution vulnerability be exploited in CVE-2021-45364?
The Code Execution vulnerability in Statamic Version through 3.2.26 can be exploited via SettingsController.php.
5
Is the existence of CVE-2021-45364 disputed?
Yes, the existence of CVE-2021-45364 is disputed.