Statamic
cpe:2.3:a:statamic:statamic:*:*:*:*:*:*:*
- < 5.73.20
- < 6.13.0
A vulnerability in Statamic CMS prior to versions 5.73.20 and 6.13.0 allows for data destruction by manipulating query parameters on Control Panel and REST API endpoints, or arguments in GraphQL queries. Exploitation can lead to the loss of content, assets, and user accounts. The Control Panel exploitation requires authentication with minimal permissions, such as 'view entries' to delete entries or 'view users' to delete users. In contrast, the REST and GraphQL API vulnerabilities do not require permissions but must be explicitly enabled without authentication. Sites using these APIs without authentication should prioritize patching.
Exploitation of this vulnerability could result in unauthorized deletion of content, assets, and user accounts.
Users should update to Statamic CMS versions 5.73.20 or 6.13.0.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.