CVE-2024-21622
Craft CMS Privilege Escalation
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Craft is a content management system. This is a potential moderate impact, low complexity privilege escalation vulnerability in Craft starting in 3.x prior to 3.9.6 and 4.x prior to 4.4.16 with certain user permissions setups. This has been fixed in Craft 4.4.16 and Craft 3.9.6. Users should ensure they are running at least those versions.
Craft es un sistema de gestiĆ³n de contenidos. Esta es una posible vulnerabilidad de escalada de privilegios de baja complejidad y impacto moderado en Craft a partir de 3.x anterior a 3.9.6 y 4.x anterior a 4.4.16 con ciertas configuraciones de permisos de usuario. Esto se ha solucionado en Craft 4.4.16 y Craft 3.9.6. Los usuarios deben asegurarse de estar ejecutando al menos esas versiones.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-12-29 CVE Reserved
- 2024-01-03 CVE Published
- 2024-01-18 EPSS Updated
- 2024-08-01 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-269: Improper Privilege Management
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
https://github.com/craftcms/cms/blob/develop/CHANGELOG.md#4511---2023-11-16 | Release Notes | |
https://github.com/craftcms/cms/blob/v3/CHANGELOG.md#396---2023-11-16 | Release Notes |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/craftcms/cms/security/advisories/GHSA-j5g9-j7r4-6qvx | 2024-01-10 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Craftcms Search vendor "Craftcms" | Craft Cms Search vendor "Craftcms" for product "Craft Cms" | >= 3.0.0 < 3.9.6 Search vendor "Craftcms" for product "Craft Cms" and version " >= 3.0.0 < 3.9.6" | - |
Affected
| ||||||
Craftcms Search vendor "Craftcms" | Craft Cms Search vendor "Craftcms" for product "Craft Cms" | >= 4.0.0 <= 4.5.15 Search vendor "Craftcms" for product "Craft Cms" and version " >= 4.0.0 <= 4.5.15" | - |
Affected
|