craftcms/cms is vulnerable to Improper Access Control
80
High Risk
Affected versions of this package had insufficient access control on several user-related controller actions in UsersController, allowing certain user management operations (such as impersonation, sending activation or password reset emails, enabling/disabling accounts, etc.) to be invoked without enforcing the appropriate permission and context checks. The patched version centralizes and strengthens these checks (userActionChecks), requiring proper post requests, control-panel context, edition, and editUsers permission before performing sensitive user actions, preventing unauthorized access and privilege escalation.
You are affected if you are using a version that falls within the vulnerable range.
craftcms/cms is vulnerable to Improper Access Control in versions 3.5.0 - 4.16.19 and 5.0.0 - 5.8.23.
Upgrade the craftcms/cms library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant