Intel

AIKIDO-2025-10604

verbb/workflow is vulnerable to Improper Handling of Insufficient Permissions or Privileges

Improper Handling of Insufficient Permissions or Privileges Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Sep 2, 2025

64

Medium Risk

This Affects:

PHPverbb/workflow
1.0.0 - 2.0.16
Fixed in 2.0.17
3.0.0 - 3.0.10
Fixed in 3.0.11
Are you affected? Scan for Free

TL;DR

Affected versions of the verbb/workflow library allow users without proper permissions to view and modify submission elements, potentially exposing or altering sensitive data.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

verbb/workflow is vulnerable to Improper Handling of Insufficient Permissions or Privileges in versions 3.0.0 - 3.0.10 and 1.0.0 - 2.0.16.

How to fix this

Upgrade the verbb/workflow library to the patch version.