PT-2026-94109 · Craft Cms · Craft Cms
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Craft CMS versions 4.8.0 through 4.18.5
Craft CMS versions 5.0.0 through 5.10.12
Description
An issue exists where the software signs an authenticated user's attacker-controlled license-shun cookie using the same key and format used to validate signed redirect parameters. This occurs because the HMAC signature is not bound to its purpose, as the
cookieValidationKey is derived from the same securityKey used for signed request parameters. An authenticated, non-administrator user can set the cookie via the license-shun endpoint and transplant the signed envelope into the redirect parameter. Upon a successful login, the system validates the signature and renders the authenticated bytes as an unsandboxed Twig template. Within this template, the map filter accepts a string callback, allowing the system() function to execute arbitrary operating-system commands as the web-server user. Exploitation requires an account using password authentication without active 2FA, the default request configuration, and the availability of the PHP system() function.Recommendations
Update Craft CMS versions 4.8.0 through 4.18.5 to version 4.18.6.
Update Craft CMS versions 5.0.0 through 5.10.12 to version 5.10.13.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Craft Cms