getkirby/kirby
cpe:2.3:a:getkirby:kirby:*:*:*:*:*:*:*
- <= 4.8.0
- >= 5.0.0, <= 5.3.3
A vulnerability exists in Kirby, an open-source content management system, prior to versions 4.9.0 and 5.4.0, allowing authenticated users to create, replace, or delete user avatars without the necessary permissions. This issue arises because avatar management is not properly restricted by user update permissions. The vulnerability can be exploited by users whose roles lack the 'user.update' or 'users.update' permissions, and it can lead to unauthorized changes in user profiles.
Exploiting this vulnerability allows for unauthorized modifications of user avatars, which are considered part of the user profile information.
Users can upgrade to Kirby versions 4.9.0 or 5.4.0, both of which include the necessary permission checks for avatar management. Instructions for downloading these versions are available on the Kirby GitHub releases page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.