craftcms/cms is vulnerable to Remote Code Execution
82
High Risk
Craft signs a license-shun cookie with the same key and format used to validate signed redirect parameters. An authenticated low-privilege user can transplant the signed cookie envelope into a redirect parameter, which then passes signature validation. During login the validated bytes are rendered as an unsandboxed Twig template, enabling arbitrary OS command execution. The fix restricts the signed cookie fields to safe MD5 and integer values so attacker-controlled Twig cannot be placed in the reusable signed envelope.
You are affected if you are using a version that falls within the vulnerable range and have password-authenticated user accounts without active two-factor authentication.
craftcms/cms is vulnerable to Remote Code Execution in versions 4.8.0 - 4.18.5 and 5.0.0 - 5.10.12.
Upgrade the craftcms/cms library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.