Intel

AIKIDO-2025-10446

craftcms/cms is vulnerable to Exposure of Sensitive System Information to an Unauthorized Control Sphere

Exposure of Sensitive System Information to an Unauthorized Control Sphere Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jul 8, 2025

13

Low Risk

This Affects:

PHPcraftcms/cms
4.0.0 - 4.16.3
Fixed in 4.16.4
5.0.0 - 5.8.3
Fixed in 5.8.4
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to Information Disclosure due to prematurely exposing sensitive parameters (announcements, baseCpUrl, cpTrigger) before validating request origin. An attacker could exploit this by crafting a malicious request to retrieve internal system details, such as admin panel URLs or trigger paths, potentially facilitating further attacks like CSRF or unauthorized access to the control panel.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

craftcms/cms is vulnerable to Exposure of Sensitive System Information to an Unauthorized Control Sphere in versions 5.0.0 - 5.8.3 and 4.0.0 - 4.16.3.

How to fix this

Upgrade the craftcms/cms library to a patch version.