AIKIDO-2024-10326

craftcms/cms is vulnerable to Incorrect Authorization

30

Low

craftcms/cms php

AIKIDO-2024-10326: craftcms/cms is vulnerable to Incorrect Authorization in versions 4.0.0 - 4.12.5 and 5.0.0 - 5.4.6.

Incorrect Authorization
Vuln in 4.0.0 - 4.12.5
Fixed in 4.12.6
Vuln in 5.0.0 - 5.4.6
Fixed in 5.4.7
No CVE available
TL;DR

Affected versions of the package are vulnerable to Incorrect Authorization. In some cases it is possible for a user to save an address he is not supposed to be able to save.

Who does this affect?

You're affected if you are using a version which is within vulnerability ranges.

How can it be fixed?

Upgrade craftcms/cms library to patch version.

Background info

Link to vendor website

Are you
to these issues?
Connect your GitHub, GitLab, Bitbucket or Azure DevOps account to start scanning your repos for free.
Start For Free
Your data won't be shared · Read-only access
Logo
© 2024 Aikido Security BV | BE0792914919
🇪🇺 Grauwpoort 1, 9000 Ghent, Belgium
🇺🇸 95 Third St, 2nd Fl, San Francisco, CA 94103, US