GHSA-j2vp-f2pv-5rj4MediumCVSS 6.5
Statamic: Unsafe method invocation via Antlers template resolution allows data destruction
🔗 CVE IDs covered (1)
📋 Description
Impact
Manipulating user-supplied input incorporated into Antlers templates could result in the loss of content and assets.
Exploitation requires a site to have templates that pass untrusted input into affected areas. It does not require authentication.
Patches
This has been fixed in 5.74.1 and 6.24.0.
🎯 Affected products2
- composer/statamic/cms:< 5.74.1
- composer/statamic/cms:>= 6.0.0, < 6.24.0