craftcms/cms is vulnerable to Remote Code Execution (RCE)
87
High Risk
EagerLoadPlan::$when accepts any PHP callable without restricting it to a Closure, and eager-load criteria reach it after sanitization that only strips on /as prefixed keys. A control panel user with only the accessCp permission can submit an eager-load when value such as system through the element search criteria, which is later invoked as a callback and executes operating system commands as the PHP web worker. The fix restricts $when to a Closure.
You are affected if you are using a version that falls within the vulnerable range and you grant control panel access to users who are not fully trusted.
craftcms/cms is vulnerable to Remote Code Execution (RCE) in versions 5.8.0 - 5.10.12.
Upgrade the craftcms/cms library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.