GHSA-vx89-p3j7-8xqcMediumCVSS 6.1
Statamic: Stored Cross-Site Scripting in Automagic Form Notification Email Template
🔗 CVE IDs covered (1)
📋 Description
Impact
The default ("automagic") form notification email rendered user-submitted values without escaping, allowing an unauthenticated form submitter to inject HTML into the notification emails sent to the configured recipients
Patches
This has been fixed in 5.74.3 and 6.24.2.
🎯 Affected products2
- composer/statamic/cms:< 5.74.3
- composer/statamic/cms:>= 6.0.0, < 6.24.2
🔗 References (6)
- https://github.com/statamic/cms/security/advisories/GHSA-vx89-p3j7-8xqc
- https://github.com/statamic/cms/pull/14959
- https://github.com/statamic/cms/commit/4ad1335e818a67249d0617f0f167a1198fb96a2c
- https://github.com/statamic/cms/releases/tag/v5.74.3
- https://github.com/statamic/cms/releases/tag/v6.24.2
- https://github.com/advisories/GHSA-vx89-p3j7-8xqc