Statamic
cpe:2.3:a:statamic:statamic:*:*:*:*:*:*:*
- < 6.3.3
- < 5.73.10
A vulnerability allowing account takeover via password reset link injection has been identified in Statamic CMS versions prior to 6.3.3 and 5.73.10. This issue arises in the password reset feature, where an attacker can capture a user's token and reset the password on their behalf. The attacker must know the email address of a valid account and the user must click the reset link in their email, even if they did not request a password reset.
Exploitation of this vulnerability allows an attacker to reset the password of a user, effectively taking over their account.
To reproduce this vulnerability, an attacker must know the email address of a valid user account. They can then initiate a password reset request, which will be sent to the user's email. The user must be tricked into clicking the reset link, after which the attacker can use the captured token to reset the user's password and gain access to their account.
Users can upgrade to Statamic versions 6.3.3 or 5.73.10 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.