VYPR
Medium severity4.8NVD Advisory· Published Dec 19, 2018· Updated Jun 17, 2026

CVE-2018-19598

CVE-2018-19598

Description

Statamic 2.10.3 allows XSS via First Name or Last Name to the /users URI in an 'Add new user' request.

Affected products

3
  • Statamic/CMSinferred
    Range: <=2.10.3
  • Statamic/Statamic2 versions
    cpe:2.3:a:statamic:statamic:2.10.3:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:statamic:statamic:2.10.3:*:*:*:*:*:*:*
    • (no CPE)range: = 2.10.3

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.