CVE-2023-48701: Statamic CMS vulnerable to Cross-site Scripting via uploaded assets
Impact HTML files crafted to look like images may be uploaded regardless of mime validation. This is only applicable on front-end forms using the "Forms" feature containing an assets field, or within the control panel which requires authentication.
Patches It has been patched on 3.4.15 and 4.36.0.
Other sources
Statamic CMS is a Laravel and Git powered content management system (CMS). Prior to versions 3.4.15 an 4.36.0, HTML files crafted to look like images may be uploaded regardless of mime validation. This is only applicable on front-end forms using the "Forms" feature containing an assets field, or within the control panel which requires authentication. This issue has been patched on 3.4.15 and 4.36.0.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-48701?
CVE-2023-48701 is a vulnerability in the Statamic CMS that allows for cross-site scripting attacks via uploaded assets.
How does the vulnerability in Statamic CMS work?
The vulnerability allows HTML files that are crafted to look like images to be uploaded regardless of mime validation, potentially enabling cross-site scripting attacks.
Which versions of Statamic CMS are affected?
Versions prior to 3.4.15 and 4.36.0 of Statamic CMS are affected.
What is the severity of CVE-2023-48701?
CVE-2023-48701 has a severity value of 7.5, indicating a high severity.
How can I fix the vulnerability in Statamic CMS?
To fix the vulnerability, upgrade to version 3.4.15 or 4.36.0 of Statamic CMS.