craftcms/cms is vulnerable to Incorrect Authorization
55
Medium Risk
Craft CMS computes the editable-structure flag for category groups from the view permission instead of the save permission. A control-panel user holding only view access to a category group can therefore reorder and re-parent its categories through the structure move-element action, which trusts the read-time authorization grant without re-checking save rights. Because a category's URI derives from its position in the tree, moving categories changes their URLs and any navigation built from the taxonomy. The fix ties structure editing to the save permission.
You are affected if you are using a version that falls within the vulnerable range and control-panel users have view access (but not save) to a category group.
craftcms/cms is vulnerable to Incorrect Authorization in versions 5.0.0 - 5.10.5.
Upgrade the craftcms/cms library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant