CVE-2024-21622
Last modified
CVE-2024-21622 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Craft is a content management system. This is a potential moderate impact, low complexity privilege escalation vulnerability in Craft starting in 3.x prior to 3.9.6 and 4.x prior to 4.4.16 with certain user permissions setups. EPSS estimates a 0.59% chance of exploitation in the next 30 days.
Description
Craft is a content management system. This is a potential moderate impact, low complexity privilege escalation vulnerability in Craft starting in 3.x prior to 3.9.6 and 4.x prior to 4.4.16 with certain user permissions setups. This has been fixed in Craft 4.4.16 and Craft 3.9.6. Users should ensure they are running at least those versions.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Craftcms | Craft Cms | >= 3.0.0, < 3.9.6 |
| Craftcms | Craft Cms | >= 4.0.0, <= 4.5.15 |
References
- https://github.com/craftcms/cms/pull/13931Issue Tracking, Patch
- https://github.com/craftcms/cms/pull/13932Issue Tracking, Patch
- https://github.com/craftcms/cms/pull/13931Issue Tracking, Patch
- https://github.com/craftcms/cms/pull/13932Issue Tracking, Patch
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-21622?
How severe is CVE-2024-21622?
How do I fix CVE-2024-21622?
Are you affected by CVE-2024-21622?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
