Cross-Site Scripting Vulnerability in Statamic Core by Statamic
CVE-2020-9322
8.8HIGH
What is CVE-2020-9322?
The /users endpoint in Statamic Core versions prior to 2.11.8 is susceptible to cross-site scripting (XSS) vulnerabilities, which can be leveraged to create unauthorized administrator accounts. A malicious actor can exploit this issue by injecting a JavaScript payload into the username field during account registration, leading to stored XSS. Additionally, the vulnerability allows for reflected XSS through manipulations of the /users PATH_INFO. This poses significant risks, as it can potentially grant attackers administrative access to the site, emphasizing the urgency for users to update to the latest version to mitigate these risks.