Craft CMS
cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*
- >= 4.0.0-RC1, <= 4.17.7
- >= 5.0.0-RC1, <= 5.9.13
A vulnerability exists in Craft CMS versions 4.0.0-RC1 prior to 4.17.8 and 5.0.0-RC1 prior to 5.9.14, allowing low-privileged authenticated users to access private asset content. This is achieved by sending a request to the 'assets/edit-image' endpoint with an arbitrary 'assetId' that the user is not authorized to view. The endpoint responds with image data or a preview redirect, without applying the necessary authorization checks for each asset, potentially leading to unauthorized disclosure of private files.
Exploitation of this vulnerability could result in unauthorized access to private asset content, allowing low-privileged users to read sensitive files they should not have access to.
Users can upgrade to Craft CMS version 4.17.8 or 5.9.14 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.