ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-9322”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-9322
Published
2025-08-08
CVSS:
8.8
ShadowTrackr CVSS:
6.8
Summary:
The /users endpoint in Statamic Core before 2.11.8 allows XSS to add an administrator user. This can be exploited via CSRF. Stored XSS can occur via a JavaScript payload in a username during account registration. Reflected XSS can occur via the /users PATH_INFO.