Kirby
cpe:2.3:a:getkirby:kirby:*:*:*:*:*:*:*
- <= 4.9.0
- >= 5.0.0, <= 5.4.0
A vulnerability exists in Kirby CMS versions prior to 4.9.1 and 5.4.1, where the `pages.access` permission is not enforced during the rendering of page drafts. This flaw allows authenticated users to access drafts of pages they should not have permission to view. The issue arises because the path resolver for the CMS router fails to properly check access rights, enabling unauthorized access to sensitive information through rendered frontend pages.
Exploitation of this vulnerability could lead to unauthorized access to page drafts, allowing authenticated users to view sensitive information ahead of its official release.
Users can update to Kirby CMS versions 4.9.1 or 5.4.1 to address this vulnerability. Instructions for updating are available in the Kirby documentation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.