Impact
The vulnerability is an authorization can invoke a forced folder move to overwrite an existing destination folder without having delete permission on that folder. The action can delete an entire subtree of assets, resulting in loss of content and potential disruption to the website. The weakness is classified as CWE‑862: Missing Authorization.
Affected Systems
The affected systems include the Craft CMS product (vendor Craft CMS). Versions 5.0.0‑RC1 through 5.9.20, inclusive, and versions 4.0.0‑RC1 through 4.17.13, inclusive, contain the flaw.
Risk and Exploitability
The CVSS score of 4.9 classifies the flaw as moderate. The EPSS score of < 1% indicates a very low but non‑zero likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that attackers would need authenticated access to the CMS, as the move operation occurs through the web interface and requires the ability to set the force parameter. The primary risk stems from accidental or malicious data deletion rather than advanced exploitation techniques.
OpenCVE Enrichment
Github GHSA