Craft CMS
cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*
- >= 4.0.0-RC1, <= 4.17.7
- >= 5.0.0-RC1, <= 5.9.13
An information disclosure vulnerability has been identified in Craft CMS versions 4.0.0-RC1 prior to 4.17.8 and 5.0.0-RC1 prior to 5.9.14. The vulnerability allows low-privileged authenticated users to access private editing metadata, including focal point information, for assets they do not have permission to view. This is possible because the 'assets/image-editor' endpoint lacks proper authorization validation, enabling unauthorized access to sensitive asset editor data.
Exploitation of this vulnerability allows unauthorized users to retrieve private editing metadata and editor context for inaccessible assets, potentially leading to further privacy violations or unauthorized actions within the CMS.
Users can upgrade to Craft CMS versions 4.17.8 or 5.9.14 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.