Описание
Craft is a content management system (CMS). Prior to 5.9.0-beta.2 and 4.17.0-beta.2, the actionSendActivationEmail() endpoint is accessible to unauthenticated users and does not require a permission check for pending users. An attacker with no prior access can trigger activation emails for any pending user account by knowing or guessing the user ID. If the attacker controls the target user’s email address, they can activate the account and gain access to the system. This vulnerability is fixed in 5.9.0-beta.2 and 4.17.0-beta.2.
Уязвимые конфигурации
Конфигурация 1Версия от 4.0.0 (исключая) до 4.17.0 (исключая)Версия от 5.0.0 (исключая) до 5.9.0 (исключая)
Одно из
cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*
cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*
cpe:2.3:a:craftcms:craft_cms:4.0.0:-:*:*:*:*:*:*
cpe:2.3:a:craftcms:craft_cms:4.0.0:rc1:*:*:*:*:*:*
cpe:2.3:a:craftcms:craft_cms:4.0.0:rc2:*:*:*:*:*:*
cpe:2.3:a:craftcms:craft_cms:4.0.0:rc3:*:*:*:*:*:*
cpe:2.3:a:craftcms:craft_cms:4.17.0:beta1:*:*:*:*:*:*
cpe:2.3:a:craftcms:craft_cms:5.0.0:-:*:*:*:*:*:*
cpe:2.3:a:craftcms:craft_cms:5.0.0:rc1:*:*:*:*:*:*
cpe:2.3:a:craftcms:craft_cms:5.9.0:beta1:*:*:*:*:*:*
EPSS
Процентиль: 19%
0.00273
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-639
Связанные уязвимости
github
5 месяцев назад
Craft CMS has unauthenticated activation email trigger with potential user enumeration
EPSS
Процентиль: 19%
0.00273
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-639