Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-30143 | The /users endpoint in Statamic Core before 2.11.8 allows XSS to add an administrator user. This can be exploited via CSRF. Stored XSS can occur via a JavaScript payload in a username during account registration. Reflected XSS can occur via the /users PATH_INFO. |
Tue, 12 Aug 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Statamic
Statamic statamic |
|
| Vendors & Products |
Statamic
Statamic statamic |
Fri, 08 Aug 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-352 CWE-79 |
|
| Metrics |
cvssV3_1
|
Fri, 08 Aug 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The /users endpoint in Statamic Core before 2.11.8 allows XSS to add an administrator user. This can be exploited via CSRF. Stored XSS can occur via a JavaScript payload in a username during account registration. Reflected XSS can occur via the /users PATH_INFO. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-08-08T14:37:50.449Z
Reserved: 2020-02-20T00:00:00.000Z
Link: CVE-2020-9322
Updated: 2025-08-08T14:37:35.457Z
Status : Deferred
Published: 2025-08-08T15:15:27.067
Modified: 2026-04-15T00:35:42.020
Link: CVE-2020-9322
No data.
OpenCVE Enrichment
Updated: 2025-08-12T11:47:26Z
EUVD