Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Craft CMS has a Missing Authorization Check on User Group Removal via save-permissions Action
Vulnerability Description
Craft CMS is a content management system (CMS). In versions 5.6.0 through 5.9.14, the `actionSavePermissions()` endpoint allows a user with only `viewUsers` permission to remove arbitrary users from all user groups. While `_saveUserGroups()` enforces per-group authorization for additions, it performs no equivalent authorization check for removals, so submitting an empty `groups` value removes all existing group memberships. Version 5.9.15 contains a patch.
CVSS Information
N/A
Vulnerability Type
授权机制缺失
Vulnerability Title
Craft CMS 安全漏洞
Vulnerability Description
Craft CMS是Craft CMS开源的一套内容管理系统(CMS)。 Craft CMS 5.6.0版本至5.9.14版本存在安全漏洞,该漏洞源于actionSavePermissions端点允许仅具有viewUsers权限的用户从所有用户组中移除任意用户,可能导致权限提升。
CVSS Information
N/A
Vulnerability Type
N/A