Collected research
Statamic CMS
Statamic CMS below 5.17.0 does not sanitise the filename supplied with an assets field on a front-end form, and it derives the storage path from that filename, so an unauthenticated uploader can put ../ sequences in the name and write outside the configured directory, overwriting configuration or dropping scripts wherever the extension allow list permits (CVE-2024-52600).
Record
- Researcher
- Sam Schroder
- Published by
- Bastion Security
- Format
- Advisory
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Sam Schroder, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .