craftcms/cms is vulnerable to Remote Code Execution
78
High Risk
Craft CMS 4.18.7 and 5.10.14 fix two distinct security issues. GHSA-5m2g-hhqr-84pc affected the cache-updates endpoint, which passed request-controlled update data into UpdatesModel construction without cleansing Yii behavior and event configuration keys; an authenticated user with Updates utility access could use that path to execute code as the PHP web user. GHSA-j5wg-m2pr-35qc affected the Twig create() function, whose denylist omitted DOM, XML, HTTP, database, and reflection classes usable as server-side data-read gadgets when untrusted values reached a non-sandboxed object template. A deployment within a vulnerable range may be exposed to either issue depending on its update permissions and template data flow.
You are affected if you are using a version that falls within a vulnerable range and authenticated users can access the Updates utility or untrusted class names or parameters can reach create() in a non-sandboxed object template.
craftcms/cms is vulnerable to Remote Code Execution in versions 3.3.16 - 4.18.6 and 5.0.0 - 5.10.13.2.
Upgrade the craftcms/cms library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.