CVE-2023-47129
Statamic CMS remote code execution via front-end form uploads
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Statmic is a core Laravel content management system Composer package. Prior to versions 3.4.13 and 4.33.0, on front-end forms with an asset upload field, PHP files crafted to look like images may be uploaded. This only affects forms using the "Forms" feature and not just _any_ arbitrary form. This does not affect the control panel. This issue has been patched in 3.4.13 and 4.33.0.
Statmic es un paquete Composer central del sistema de gestión de contenidos Laravel. Antes de las versiones 3.4.13 y 4.33.0, en los formularios frontales con un campo de carga de activos, se podían cargar archivos PHP manipulados para que parecieran imágenes. Esto sólo afecta a los formularios que utilizan la función "Formularios" y no sólo a cualquier formulario arbitrario. Esto no afecta al panel de control. Este problema se solucionó en 3.4.13 y 4.33.0.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2023-10-30 CVE Reserved
- 2023-11-10 CVE Published
- 2023-11-13 First Exploit
- 2024-09-03 CVE Updated
- 2024-11-16 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-434: Unrestricted Upload of File with Dangerous Type
CAPEC
References (4)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/Cyber-Wo0dy/CVE-2023-47129 | 2023-11-13 |
URL | Date | SRC |
---|---|---|
https://github.com/statamic/cms/commit/098ef8024d97286ca501273c18ae75b646262d75 | 2023-11-17 | |
https://github.com/statamic/cms/commit/f6c688154f6bdbd0b67039f8f11dcd98ba061e77 | 2023-11-17 |
URL | Date | SRC |
---|---|---|
https://github.com/statamic/cms/security/advisories/GHSA-72hg-5wr5-rmfc | 2023-11-17 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Statamic Search vendor "Statamic" | Statamic Search vendor "Statamic" for product "Statamic" | < 3.4.13 Search vendor "Statamic" for product "Statamic" and version " < 3.4.13" | - |
Affected
| ||||||
Statamic Search vendor "Statamic" | Statamic Search vendor "Statamic" for product "Statamic" | >= 4.0.0 < 4.33.0 Search vendor "Statamic" for product "Statamic" and version " >= 4.0.0 < 4.33.0" | - |
Affected
|