Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-3371 | Statmatic is a Laravel and Git powered content management system (CMS). Prior to version 5.17.0, assets uploaded with appropriately crafted filenames may result in them being placed in a location different than what was configured. The issue affects front-end forms with `assets` fields and other places where assets can be uploaded, although users would need upload permissions anyway. Files can be uploaded so they would be located on the server in a different location, and potentially override existing files. Traversal outside an asset container is not possible. This path traversal vulnerability has been fixed in 5.17.0. |
Github GHSA |
GHSA-p7f6-8mcm-fwv3 | Statamic CMS has a Path Traversal in Asset Upload |
Tue, 03 Dec 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Statamic
Statamic statamic |
|
| CPEs | cpe:2.3:a:statamic:statamic:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Statamic
Statamic statamic |
|
| Metrics |
ssvc
|
Tue, 19 Nov 2024 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Statmatic is a Laravel and Git powered content management system (CMS). Prior to version 5.17.0, assets uploaded with appropriately crafted filenames may result in them being placed in a location different than what was configured. The issue affects front-end forms with `assets` fields and other places where assets can be uploaded, although users would need upload permissions anyway. Files can be uploaded so they would be located on the server in a different location, and potentially override existing files. Traversal outside an asset container is not possible. This path traversal vulnerability has been fixed in 5.17.0. | |
| Title | Statamic CMS has Path Traversal in Asset Upload | |
| Weaknesses | CWE-22 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-12-03T17:18:17.282Z
Reserved: 2024-11-14T15:05:46.770Z
Link: CVE-2024-52600
Updated: 2024-12-03T17:18:04.997Z
Status : Deferred
Published: 2024-11-19T17:15:56.030
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-52600
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA