Impact
The vulnerability resides in the actionReorderSets method of Craft CMS’s GlobalsController. A flaw allows an attacker to reorder global sets without supplying appropriate authorization, which results in an authorization bypass (CWE-285). This enables an attacker to move settings beyond their permitted scope, potentially facilitating further privileged activity.
Affected Systems
Craft CMS versions 4.18.0 and earlier, including 4.18.0.1, are affected. All deployments of this CMS that have not yet upgraded to version 4.18.1 or newer are vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is <1%, indicating a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack can be carried out remotely by sending a crafted request to the reorder‑sets endpoint, possibly requiring network access to the CMS. Given the limited exploitation likelihood, immediate patching remains the most prudent approach.
OpenCVE Enrichment