Pixel & Tonic Craft CMS
cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*
- <= 5.9.5
A missing authorization vulnerability has been identified in Craft CMS versions through 5.9.5. This vulnerability exists in the migrate endpoint of the application.
Exploitation of this vulnerability allows for authentication bypass, enabling unauthorized users to access functionalities that require authentication.
To reproduce this vulnerability, send a POST request to the '/actions/app/migrate' endpoint without proper authorization. This can be done using a tool like curl.
Users are advised to update Craft CMS to version 5.9.6 or later, where this vulnerability has been addressed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.