An issue was discovered in Craft CMS before 3.6.7. In some circumstances, a potential Remote Code Execution vulnerability existed on sites that did not restrict administrative changes (if an attacker were somehow able to hijack an administrator's session).
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://github.com/craftcms/cms/blob/develop/CHANGELOG.md#security | third party advisory release notes |
https://github.com/craftcms/cms/commit/c17728fa0bec11d3b82c34defe0930ed409aec38 | third party advisory patch |
https://github.com/craftcms/cms/blob/develop/CHANGELOG.md#367---2021-02-23 | third party advisory release notes |