Craft CMS
cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*
- >= 5.0.0-RC1, <= 5.9.14
- >= 4.0.0-RC1, <= 4.17.8
A server-side request forgery (SSRF) vulnerability has been identified in Craft CMS versions 4.x prior to 4.17.9 and 5.x prior to 5.9.15. The vulnerability arises in the GraphQL asset upload mutations, where the application fails to properly validate URL schemes. This oversight allows attackers to exploit the Gopher protocol to send raw TCP commands to internal services, potentially bypassing security filters. Exploitation requires permissions to edit and create assets in the affected volume.
Exploitation of this vulnerability could allow an attacker to access internal services by sending crafted requests that bypass certain string-matching filters, such as those looking for '127.0.0.1'.
Users can update to Craft CMS versions 4.17.9 or 5.9.15 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.