craftcms/cms is vulnerable to Remote Code Execution
82
High Risk
Craft CMS cleanses the outer element-search condition array but re-decodes and merges the JSON in the condition config without cleansing it again. Yii special configuration keys hidden inside that JSON string survive the first cleanse and are interpreted as behavior and event configuration during field-layout creation. An authenticated control-panel user can inject these keys to execute operating-system commands as the web user. The fix re-cleanses the decoded configuration before it is applied.
You are affected if you are using a version that falls within the vulnerable range and authenticated control-panel users can submit element-search condition configuration.
craftcms/cms is vulnerable to Remote Code Execution in versions 4.0.0 - 4.18.1 and 5.0.0 - 5.10.5.
Upgrade the craftcms/cms library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant