First published: Wed Jan 03 2024(Updated: )
### Impact This is a potential moderate impact, low complexity privilege escalation vulnerability in Craft with certain user permissions setups. ### Patches This has been fixed in Craft 4.4.16 and Craft 3.9.6. Users should ensure they are running at least those versions. ### References https://github.com/craftcms/cms/pull/13932 https://github.com/craftcms/cms/pull/13931 https://github.com/craftcms/cms/blob/develop/CHANGELOG.md#4511---2023-11-16 https://github.com/craftcms/cms/blob/v3/CHANGELOG.md#396---2023-11-16
Credit: security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/craftcms/cms | >=3.0.0<=3.9.5 | 3.9.6 |
composer/craftcms/cms | >=4.0.0-RC1<=4.5.10 | 4.5.11 |
Craftcms Craft Cms | >=3.0.0<3.9.6 | |
Craftcms Craft Cms | >=4.0.0<=4.5.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.