craftcms/cms is vulnerable to Privilege Escalation
43
Medium Risk
craftcms/cms lets control panel users holding administrateUsers activate other accounts. The activate-user action did not require the caller to be an admin when the target account is an admin. A non-admin with that permission could therefore activate admin accounts. The fix requires the caller to be an admin before activating an admin target.
You are affected if you are using a version that falls within the vulnerable range and you have granted the administrateUsers permission to non-admin control panel users.
craftcms/cms is vulnerable to Privilege Escalation in versions 3.1.0 - 5.10.11.
Upgrade the craftcms/cms library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant