craftcms/cms is vulnerable to Arbitrary File Read
30
Low Risk
The Twig create function in Craft CMS instantiates arbitrary PHP classes restricted only by a short blocklist that omits the file-object class. In non-sandboxed admin-configured contexts such as entry-type title and URI formats, this enables reading arbitrary files from the server, including environment files with the security key and database credentials. Exploitation requires admin access with administrative changes allowed, and file contents are surfaced as rendered entry titles. The fix adds the file-reading class to the blocklist.
You are affected if you are using a version that falls within the vulnerable range and you allow administrative changes so entry-type title or URI formats can be edited.
craftcms/cms is vulnerable to Arbitrary File Read in versions 4.0.0 - 4.18.1 and 5.0.0 - 5.10.5.
Upgrade the craftcms/cms library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant