【中危】cms 安全更新(GHSA-h77m-qrj7-jxcw)
安全情报快照 · 风险级别:中危 · CVSS:6.1 · CVE-2026-54243 · GHSA-h77m-qrj7-jxcw
先看结论
cms存在安全风险,>= 6.0.0, < 6.20.1 受影响,建议升级至 6.20.1。
影响范围
| 生态 | 组件 | 受影响版本 | 首个修复版本 |
|---|---|---|---|
| composer | statamic/cms |
>= 6.0.0, < 6.20.1 | 6.20.1 |
| composer | statamic/cms |
< 5.73.24 | 5.73.24 |
处置建议
优先将 statamic/cms 升级至 6.20.1 或更高版本;升级前请结合业务依赖完成兼容性验证。
上游技术详情(原文)
Impact
Form submission values were not neutralized for spreadsheet formula characters when exported to CSV. A submission containing a value beginning with a formula trigger character (e.g. = , + , - , @ ) could be interpreted as a live formula when a Control Panel user opens the export in a spreadsheet application. Form submissions can come from unauthenticated front-end visitors, so the malicious value can be supplied by an anonymous user and is later triggered by an editor opening the export.
Exploitation affects the spreadsheet application used to open the export, not the Statamic application or server; the data at risk is the form submission data the exporting user is already authorized to view.
Patches
This has been fixed in 5.73.24 and 6.20.1.
来源与许可
- GitHub Advisory GHSA-h77m-qrj7-jxcw
- https://github.com/statamic/cms/security/advisories/GHSA-h77m-qrj7-jxcw
本页自动同步 GitHub Advisory Database 的公开数据,并保留上游原文供核验;不宣称原创分析。数据许可:CC-BY-4.0。
评论
登录 后参与讨论。
还没有评论,来说两句。