安全速报自动同步 · 保留上游原文

【中危】cms 安全更新(GHSA-h77m-qrj7-jxcw)

S
KHack 安全情报
2026/6/27 发布 · 2 阅读

安全情报快照 · 风险级别:中危 · CVSS:6.1 · CVE-2026-54243 · GHSA-h77m-qrj7-jxcw

先看结论

cms存在安全风险,>= 6.0.0, < 6.20.1 受影响,建议升级至 6.20.1。

影响范围

生态 组件 受影响版本 首个修复版本
composer statamic/cms >= 6.0.0, < 6.20.1 6.20.1
composer statamic/cms < 5.73.24 5.73.24

处置建议

优先将 statamic/cms 升级至 6.20.1 或更高版本;升级前请结合业务依赖完成兼容性验证。

上游技术详情(原文)

Impact

Form submission values were not neutralized for spreadsheet formula characters when exported to CSV. A submission containing a value beginning with a formula trigger character (e.g.  = ,  + ,  - ,  @ ) could be interpreted as a live formula when a Control Panel user opens the export in a spreadsheet application. Form submissions can come from unauthenticated front-end visitors, so the malicious value can be supplied by an anonymous user and is later triggered by an editor opening the export.

Exploitation affects the spreadsheet application used to open the export, not the Statamic application or server; the data at risk is the form submission data the exporting user is already authorized to view.

Patches

This has been fixed in 5.73.24 and 6.20.1.

来源与许可

本页自动同步 GitHub Advisory Database 的公开数据,并保留上游原文供核验;不宣称原创分析。数据许可:CC-BY-4.0。

评论

还没有评论,来说两句。