Craft CMS Privilege Escalation
Package
Affected versions
>= 4.0.0-RC1, <= 4.5.10
>= 3.0.0, <= 3.9.5
Patched versions
4.5.11
3.9.6
Description
Published by the National Vulnerability Database
Jan 3, 2024
Published to the GitHub Advisory Database
Jan 3, 2024
Reviewed
Jan 3, 2024
Last updated
Jan 3, 2024
Impact
This is a potential moderate impact, low complexity privilege escalation vulnerability in Craft with certain user permissions setups.
Patches
This has been fixed in Craft 4.4.16 and Craft 3.9.6. Users should ensure they are running at least those versions.
References
craftcms/cms#13932
craftcms/cms#13931
https://github.com/craftcms/cms/blob/develop/CHANGELOG.md#4511---2023-11-16
https://github.com/craftcms/cms/blob/v3/CHANGELOG.md#396---2023-11-16
References