Intel

AIKIDO-2025-10090

craftcms/cms is vulnerable to Improper Input Validation

Improper Input Validation Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Feb 12, 2025

61

Medium Risk

This Affects:

PHPcraftcms/cms
1.0.0 - 4.14.4
Fixed in 4.14.5
5.0.0 - 5.6.5
Fixed in 5.6.6
Are you affected? Scan for Free

TL;DR

Affected versions of this package do not properly sanitize usernames, allowing the use of URLs. This could be exploited as a phishing attack vector, as an attacker could craft usernames that resemble legitimate links, potentially deceiving users into clicking on them.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

craftcms/cms is vulnerable to Improper Input Validation in versions 1.0.0 - 4.14.4 and 5.0.0 - 5.6.5.

How to fix this

Upgrade the craftcms/cms library to a patch version.