Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-1981 | Statamic is a flat-first, Laravel and Git powered content management system. Prior to version 4.10.0, the SVG tag does not sanitize malicious SVG. Therefore, an attacker can exploit this vulnerability to perform cross-site scripting attacks using SVG, even when using the `sanitize` function. Version 4.10.0 contains a patch for this issue. |
Github GHSA |
GHSA-6r5g-cq4q-327g | Statamic's Antlers sanitizer cannot effectively sanitize malicious SVG |
Thu, 24 Oct 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Statamic cms
|
|
| CPEs | cpe:2.3:a:statamic:cms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Statamic cms
|
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-10-24T18:06:44.250Z
Reserved: 2023-06-27T15:43:18.388Z
Link: CVE-2023-36828
Updated: 2024-08-02T17:01:09.623Z
Status : Modified
Published: 2023-07-05T22:15:10.113
Modified: 2024-11-21T08:10:41.293
Link: CVE-2023-36828
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA