Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-53vf-c43h-j2x9

Опубликовано: 05 янв. 2026
Источник: github
Github: Прошло ревью
CVSS4: 4.9

Описание

Craft CMS vulnerable to potential information disclosure via unchecked asset relocation

Authenticated users on a Craft installation could potentially expose sensitive assets via their user profile photo via maliciously crafted requests.

Users should update to the patched versions (5.8.21 and 4.16.17) to mitigate the issue.

Resources:

https://github.com/craftcms/cms/commit/4bcb0db554e273b66ce3b75263a13414c2368fc9

https://github.com/craftcms/cms/commit/4bcb0db554e273b66ce3b75263a13414c2368fc9

Пакеты

Наименование

craftcms/cms

composer
Затронутые версииВерсия исправления

>= 5.0.0-RC1, <= 5.8.20

5.8.21

Наименование

craftcms/cms

composer
Затронутые версииВерсия исправления

>= 4.0.0-RC1, <= 4.16.16

4.16.17

EPSS

Процентиль: 12%
0.0004
Низкий

4.9 Medium

CVSS4

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 6.5
nvd
около 1 месяца назад

Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16, authenticated users on a Craft installation could potentially expose sensitive assets via their user profile photo via maliciously crafted requests. Users should update to the patched versions (5.8.21 and 4.16.17) to mitigate the issue.

EPSS

Процентиль: 12%
0.0004
Низкий

4.9 Medium

CVSS4

Дефекты

CWE-200