craftcms/cms is vulnerable to Exposure of Sensitive System Information to an Unauthorized Control Sphere
20
Low Risk
Affected versions of this package are vulnerable to Information Disclosure, where the 'photoId' attribute was improperly included in the safe attributes list, allowing attackers to exploit mass assignment mechanisms to read or manipulate photo identifiers, potentially leading to unauthorized access to sensitive image data. The patch resolves this by explicitly removing 'photoId' from the safe attributes array using ArrayHelper::withoutValue.
You are affected if you are using a version that falls within the vulnerable range.
craftcms/cms is vulnerable to Exposure of Sensitive System Information to an Unauthorized Control Sphere in versions 5.0.0 - 5.8.20 and 4.0.0 - 4.16.16.
Upgrade the craftcms/cms library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant