craftcms/cms is vulnerable to Remote Code Execution
82
High Risk
Craft CMS 5.10.12 fixes three independently reported issues. GHSA-qj4v-m29p-fj4m allowed stringified field-layout configuration to bypass cleansing and restore unsafe Yii behavior or event keys after decoding, leading to code execution. GHSA-jqf5-vfg6-8cx5 allowed a non-admin user administrator to activate a deactivated administrator account without the required admin-target check. GHSA-9wcj-wqqh-cqvg allowed asset transform criteria to select an arbitrary class at the normalization sink, providing a path to code execution. A deployment within the vulnerable range may be exposed to one or more of these issues when untrusted users have the relevant control panel permissions.
You are affected if you are using a version that falls within the vulnerable range and untrusted authenticated users can access field-layout configuration, view assets through the control panel, or administrate users.
craftcms/cms is vulnerable to Remote Code Execution in versions 5.0.0 - 5.10.11.
Upgrade the craftcms/cms library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.