craftcms/cms is vulnerable to Remote Code Execution (RCE)
87
High Risk
Conditions::createCondition() JSON-decodes a condition.config value and merges it back into the outer config without re-running the sanitizer that strips on and as behavior/event keys. An authenticated control panel user can smuggle Yii behavior or event configuration through this decoded value, which Yii then interprets during object construction, allowing arbitrary command execution as the PHP web user. The fix re-sanitizes the decoded config before it reaches object construction.
You are affected if you are using a version that falls within the vulnerable range and you grant control panel access to users who are not fully trusted.
craftcms/cms is vulnerable to Remote Code Execution (RCE) in versions 4.0.0 - 4.18.1 and 5.0.0 - 5.10.5.
Upgrade the craftcms/cms library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.