HIGH8.3
GHSA-72hg-5wr5-rmfc
Statamic CMS remote code execution via front-end form uploads
Quick fix
GHSA-72hg-5wr5-rmfc — statamic/cms: upgrade to the fixed version with the command below.
composer require statamic/cms:^4.33.0Details
### Impact On front-end forms with an asset upload field, PHP files crafted to look like images may be uploaded regardless of mime validation rules. This only affects forms using the "Forms" feature and not just _any_ arbitrary form. This does not affect the control panel.
### Patches It has been patched in 3.4.13 and 4.33.0.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/statamic/cms/security/advisories/GHSA-72hg-5wr5-rmfc[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-47129[ADVISORY]
- https://github.com/statamic/cms/commit/098ef8024d97286ca501273c18ae75b646262d75[WEB]
- https://github.com/statamic/cms/commit/f6c688154f6bdbd0b67039f8f11dcd98ba061e77[WEB]
- https://github.com/statamic/cms[PACKAGE]