A Time-of-Check-Time-of-Use (TOCTOU) race condition exists in Craft CMS’s token validation service for tokens that explicitly set a limited usage. The getTokenRoute() method reads a token’s usage count, checks if it’s within limits, then updates the database in separate non-atomic operations. By sending concurrent requests, an attacker can use a single-use impersonation token multiple times before the database update completes.
To make this work, an attacker needs to obtain a valid user account impersonation URL with a non-expired token via some other means and exploit a race condition while bypassing any rate-limiting rules in place.
For this to be a privilege escalation, the impersonation URL must include a token for a user account with more permissions than the current user.
References
https://github.com/craftcms/cms/commit/3e4afe18279951c024c64896aa2b93cda6d95fdf
A stored Cross-site Scripting (XSS) vulnerability exists in the editableTable.twig component when using the html column type. The application fails to sanitize the input, allowing an attacker to execute arbitrary JavaScript when another user views a page with the malicious table field.
Prerequisites An administrator account allowAdminChanges must be enabled in production, which is against our security recommendations.
Steps to Reproduce 1. Navigate to Settings → Fields and create a new field with Type: Table 1. Add a Column Heading and set Column Type to Single-line text - Note: The vulnerable Column Type is html, but it's not available in the UI dropdown. 1. In Default Values section, add a row with the following payload: html <img src=x onerror="alert('XSS')"> 1. Enable Static Rows 1. Intercept the Save Field request using a proxy tool (e.g., Burp Suite) or use cURL directly 1. Modify the request body and change the types[craft-fields-Table][columns][col3][type] parameter from singleline to html 1. Forward the request to save the field 1. Use the field in any object (e.g. user profile fields) → then visit the any user's profile 1. Notice the XSS execution 1. The XSS will also trigger when an administrator attempts to edit this field, as the malicious payload is executed within the field configuration page, too.
Resources
https://github.com/craftcms/cms/commit/f5d488d9bb6eff7670ed2c2fe30e15692e92c52b