Statamic
cpe:2.3:a:statamic:statamic:*:*:*:*:*:*:*
- >= 6.0.0, < 6.2.3
A stored cross-site scripting vulnerability has been identified in Statamic CMS versions 6.0.0 prior to 6.2.3. This issue allows authenticated users with content creation permissions to inject malicious JavaScript into content titles. The injected script executes when the content is viewed by users with higher privileges. Exploitation of this vulnerability could lead to the creation of super admin accounts.
Exploitation of this vulnerability allows for privilege escalation, enabling the creation of super admin accounts.
Users can upgrade to Statamic CMS version 6.2.3 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.