craftcms/cms is vulnerable to Information Disclosure
37
Low Risk
The web controller's model success JSON response serializes the full model, which includes the model's control panel edit URL. For requests that are not control panel requests and are made by users without control panel access, that control panel edit URL is still included in the response body. This exposes an internal control panel edit URL to front-end contexts and users who should not see it. The fix removes the cpEditUrl from the response data when the request is not a control panel request and the current user cannot access the control panel.
You are affected if you are using a version that falls within the vulnerable range and your site returns model success responses on front-end (non-control-panel) requests to users without control panel access.
craftcms/cms is vulnerable to Information Disclosure in versions 4.0.0 - 5.10.8.1.
Upgrade the craftcms/cms library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant