Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v64r-7wg9-23pr

Опубликовано: 05 янв. 2026
Источник: github
Github: Прошло ревью
CVSS4: 7

Описание

Unauthenticated Craft CMS users can trigger a database backup

Unauthenticated users can trigger database backup operations the updater/backup action, potentially leading to resource exhaustion or information disclosure.

Users should update to the patched versions (5.8.21 and 4.16.17) to mitigate the issue.

Craft 3 users should update to the latest Craft 4 and 5 releases, which include the fixes.

References:

https://github.com/craftcms/cms/commit/f83d4e0c6b906743206b4747db4abf8164b8da39

https://github.com/craftcms/cms/blob/5.x/CHANGELOG.md#5821---2025-12-04

Affected Endpoints

  • POST /admin/actions/updater/backup (unauthenticated)

Vulnerability Details

Root Cause

All updater/* actions are explicitly configured with anonymous access:

// BaseUpdaterController.php protected array|bool|int $allowAnonymous = self::ALLOW_ANONYMOUS_LIVE | self::ALLOW_ANONYMOUS_OFFLINE;

Attack Vector

  1. Send unauthenticated POST request to /admin/actions/updater/backup
  2. Database backup executes with configured backupCommand

Пакеты

Наименование

craftcms/cms

composer
Затронутые версииВерсия исправления

>= 5.0.0-RC1, <= 5.8.20

5.8.21

Наименование

craftcms/cms

composer
Затронутые версииВерсия исправления

>= 3.0.0, <= 4.16.16

4.16.17

EPSS

Процентиль: 32%
0.00121
Низкий

7 High

CVSS4

Дефекты

CWE-202
CWE-770

Связанные уязвимости

CVSS3: 9.1
nvd
около 1 месяца назад

Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 3.0.0 through 4.16.16, unauthenticated users can trigger database backup operations via specific admin actions, potentially leading to resource exhaustion or information disclosure. Users should update to the patched versions (5.8.21 and 4.16.17) to mitigate the issue. Craft 3 users should update to the latest Craft 4 and 5 releases, which include the fixes.

EPSS

Процентиль: 32%
0.00121
Низкий

7 High

CVSS4

Дефекты

CWE-202
CWE-770