CVE-2020-9322

high

Description

The /users endpoint in Statamic Core before 2.11.8 allows XSS to add an administrator user. This can be exploited via CSRF. Stored XSS can occur via a JavaScript payload in a username during account registration. Reflected XSS can occur via the /users PATH_INFO.

References

https://web.archive.org/web/20200304174034/www.statamic.com/changelog#2.11.18

https://statamic.com/changelog#2.11.18

https://gist.github.com/kernelsndrs/86b78e869d481566223914ec7d4fc881

Details

Source: Mitre, NVD

Published: 2025-08-08

Updated: 2025-08-08

Risk Information

CVSS v2

Base Score: 9

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 8.8

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.0002