VDB
Sign up
MEDIUM5.4

GHSA-j5g9-j7r4-6qvx

Craft CMS Privilege Escalation

Quick fix

GHSA-j5g9-j7r4-6qvx — craftcms/cms: upgrade to the fixed version with the command below.

composer require craftcms/cms:^4.5.11

Details

### Impact

This is a potential moderate impact, low complexity privilege escalation vulnerability in Craft with certain user permissions setups.

### Patches

This has been fixed in Craft 4.4.16 and Craft 3.9.6. Users should ensure they are running at least those versions.

### References

https://github.com/craftcms/cms/pull/13932 https://github.com/craftcms/cms/pull/13931 https://github.com/craftcms/cms/blob/develop/CHANGELOG.md#4511---2023-11-16 https://github.com/craftcms/cms/blob/v3/CHANGELOG.md#396---2023-11-16

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/craftcms/cms
Introduced in: 4.0.0-RC1Fixed in: 4.5.11
Fixcomposer require craftcms/cms:^4.5.11
Packagist/craftcms/cms
Introduced in: 3.0.0Fixed in: 3.9.6
Fixcomposer require craftcms/cms:^3.9.6

References