Web Hack List

Collected research

Statamic CMS

Statamic CMS below 5.17.0 does not sanitise the filename supplied with an assets field on a front-end form, and it derives the storage path from that filename, so an unauthenticated uploader can put ../ sequences in the name and write outside the configured directory, overwriting configuration or dropping scripts wherever the extension allow list permits (CVE-2024-52600).

Record

Researcher
Sam Schroder
Published by
Bastion Security
Format
Advisory
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Sam Schroder, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .