craftcms/cms is vulnerable to Missing Authorization
43
Medium Risk
The charts controller action that returns new-user registration data in Craft CMS omits the view-users permission check applied elsewhere for user data. Any authenticated control-panel user can request time-series registration counts for the whole site or for an arbitrary user group by manipulating the group parameter. This discloses aggregate user counts and registration trends that normally require the view-users permission. The fix restricts the action to authorized control-panel requests.
You are affected if you are using a version that falls within the vulnerable range and authenticated control-panel users can call the charts new-users data action without holding the view-users permission.
craftcms/cms is vulnerable to Missing Authorization in versions 4.0.0 - 4.18.0.1 and 5.0.0 - 5.10.2.
Upgrade the craftcms/cms library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant