craftcms/cms is vulnerable to Remote Code Execution
82
High Risk
Craft CMS 5.10.13 fixes six independently reported security issues. GHSA-5jmw-g85v-7jv2 allowed signed redirect data to reach unsandboxed Twig rendering and execute code; GHSA-9c4j-cjw3-r3xx allowed request-controlled eager-loading callbacks to invoke arbitrary PHP functions; GHSA-hfjh-gw6x-7pv5 allowed installer-supplied site values to expand environment secrets during a database outage; GHSA-4mgp-5vf2-7c9m allowed nested eager-loading criteria to reach a database query and produce blind SQL injection; GHSA-h9jh-v8vc-m5rp allowed lower-privilege content to become stored XSS through Generated Field index values; and GHSA-6fp2-8j9w-7mj8 allowed view-only users to reorder peer-owned nested elements. A deployment within the vulnerable range may be exposed to one or more of these issues depending on its control panel roles, GraphQL and field configuration, and outage conditions.
You are affected if you are using a version that falls within the vulnerable range and grant non-admin users control panel access, render lower-trust content through Generated Fields, or keep the PHP application reachable while its database is unavailable.
craftcms/cms is vulnerable to Remote Code Execution in versions 5.0.0 - 5.10.12.
Upgrade the craftcms/cms library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.