MEDIUM4.3
GHSA-qxh3-jgvh-x55j
Connect-CMS Privilege Escalation Vulnerability
Quick fix
GHSA-qxh3-jgvh-x55j — opensource-workshop/connect-cms: upgrade to the fixed version with the command below.
composer require opensource-workshop/connect-cms:^1.7.2Details
### Impact(影響)
There is a Privilege Escalation Vulnerability on the management system of Connect-CMS. Affercted Version : Connect-CMS 1.7.1, 2.3.1 and earlier
### Patches(修正バージョン)
version 1.7.2, 2.3.1
### Workarounds(運用回避手段)
Upgrade Connect-CMS to latest version
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/opensource-workshop/connect-cms
Introduced in:
0Fixed in: 1.7.2Fix
composer require opensource-workshop/connect-cms:^1.7.2Packagist/opensource-workshop/connect-cms
Introduced in:
2.0.0Fixed in: 2.3.2Fix
composer require opensource-workshop/connect-cms:^2.3.2