RSS   Vulnerabilities for 'Framework cms'   RSS

2017-07-24
 
CVE-2017-11422

CWE-732
 

 
Statamic framework before 2.6.0 does not correctly check a session's permissions when the methods from a user's class are called. Problematic methods include reset password, create new account, create new role, etc.

 

 >>> Vendor: Statamic 2 Products
Framework cms
Statamic


Copyright 2024, cxsecurity.com

 

Back to Top