GHSA-rvmm-v933-jgxq: Composer/craftcms/cms vulnerability
ChartsController::actionGetNewUsersData() at /actions/charts/get-new-users-data is missing a requirePermission('viewUsers') authorization check. Any authenticated control panel user, regardless of permissions beyond accessCp, can POST to this endpoint to receive time-series user registration counts for the entire site or for an arbitrary user group ID.
The viewUsers permission is consistently required throughout the control panel before exposing user-related data, but this action enforces only the base accessCp check inherited from the framework.
Each call returns the total count of users who joined the specified group in the requested period.
Impact
Any control panel user with only accessCp permission can obtain the total number of registered users and their registration date distribution across any time window.
In installations with multiple editor roles, this allows a low-privilege control panel user to infer user group sizes and registration trends that would normally require the viewUsers permission to access.
No user PII (name, email, password) is disclosed; only aggregate counts and timestamps are returned. Confidentiality impact is low. No integrity or availability impact.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/craftcms/cmsto a version that resolves this vulnerability.Fixed in 5.10.3 - Upgrade
Upgrade
composer/craftcms/cmsto a version that resolves this vulnerability.Fixed in 4.18.1 - Configuration
Add an explicit authorization check to requirePermission('viewUsers') to ChartsController::actionGetNewUsersData() so only users with viewUsers can access /actions/charts/get-new-users-data instead of relying on the base inherited accessCp permission.
Craft CMS ChartsController::actionGetNewUsersData() (endpoint /actions/charts/get-new-users-data) requirePermission('viewUsers') authorization check = required
Event History
Frequently Asked Questions
What is the severity of GHSA-rvmm-v933-jgxq?
The severity of GHSA-rvmm-v933-jgxq is categorized as risk 13.
What does GHSA-rvmm-v933-jgxq exploit in Craft CMS?
GHSA-rvmm-v933-jgxq exploits a missing authorization check in the ChartsController's actionGetNewUsersData method.
How do I fix GHSA-rvmm-v933-jgxq?
To fix GHSA-rvmm-v933-jgxq, ensure to add the requirePermission('viewUsers') authorization check to the relevant endpoint.
What can an attacker do under GHSA-rvmm-v933-jgxq?
An attacker can POST to the vulnerable endpoint and retrieve user registration data without proper permissions.
Who is affected by GHSA-rvmm-v933-jgxq?
Any authenticated control panel user in Craft CMS with accessCp can be affected by GHSA-rvmm-v933-jgxq.