Kirby
cpe:2.3:a:getkirby:kirby:*:*:*:*:*:*:*
- <= 4.9.0
- >= 5.0.0, <= 5.4.0
A vulnerability exists in Kirby, an open-source content management system, in versions prior to 4.9.1 and 5.4.1. The issue arises from the content-locking feature, which fails to verify a user's access permissions before disclosing lock information. This feature is designed to prevent conflicting edits by multiple users by indicating who is currently editing a model. However, the system inadvertently exposes the email addresses and identifiers of users, including those with administrative privileges, to low-privilege authenticated Panel users whose roles restrict access to user information. This flaw could be exploited to enumerate admin accounts, facilitate phishing attacks, and conduct credential-stuffing attacks against the affected Kirby installation or other sites.
Exploitation of this vulnerability allows unauthorized access to the email addresses and user IDs of individuals currently editing a model in the Kirby Panel, including administrators. Such information could be used to target phishing attacks, enumerate admin accounts, and launch credential-stuffing attacks.
Users can update to Kirby versions 4.9.1 or 5.4.1 to address this vulnerability. In these versions, the content-lock information is filtered according to the user's permissions, ensuring that only authorized users can access details about who is editing a model.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.