craftcms/cms is vulnerable to Improper Authorization
50
Medium Risk
Affected versions of this package are vulnerable to permission escalation because certain GraphQL asset mutation logic did not enforce correct ownership checks, allowing a user with privileges to save or create assets to potentially act on volumes they shouldn’t have access to. The referenced commit adds explicit checks to ensure the asset’s volume ID matches the expected volume and requires the appropriate schema action for unauthorized attempts, preventing attackers from exploiting the mutation to escalate privileges or modify resources outside their permitted scope.
You are affected if you are using a version that falls within the vulnerable range.
craftcms/cms is vulnerable to Improper Authorization in versions 3.5.0 - 4.16.17 and 5.0.0 - 5.8.21.
Upgrade the craftcms/cms library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant