craftcms/cms is vulnerable to Improper Authorization
78
High Risk
The element-save action in Craft CMS treats a User element's new-password field as mass-assignable because its validator is only marked safe with no scenario restriction. This lets any authenticated user set their own password without supplying the current password or an elevated session, bypassing the dedicated set-password flow that enforces session verification. A user holding the edit-users permission can also change other users' passwords, including administrators, enabling account takeover. The fix restricts password assignment to the intended elevated-session flow.
You are affected if you are using a version that falls within the vulnerable range and authenticated control-panel users can save User elements (any user can set their own password without the current password; users with edit-users can change other users' passwords).
craftcms/cms is vulnerable to Improper Authorization in versions 5.0.0 - 5.10.7.
Upgrade the craftcms/cms library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant