Impact
The vulnerability enables an authenticated Backpack admin to modify a user’s password, authentication column, or other fillable attributes by sending a POST to /admin/edit-account-info. The controller passes all unchecked request fields except the CSRF token directly to the user model, bypassing the validation rules defined in AccountInfoRequest. As a result, a plaintext password sent by the attacker is automatically hashed and stored, turning a temporary session into a persistent account takeover without requiring the old password. The flaw also allows changing the authentication email, potentially enabling later password‑reset hijacking, and opens the door for deployment‑specific privilege escalation if other sensitive fields are writable. The vulnerability is mitigated in Backpack:CRUD 6.8.11 and 7.0.34.
Affected Systems
All installations of Laravel‑Backpack:CRUD that use MyAccountController and are running an earlier version than 6.8.11 or 7.0.34 are affected. Users of the default Laravel 11 user model that automatically hashes incoming plaintext passwords are especially vulnerable because the change is persisted without requiring the old password.
Risk and Exploitability
The CVSS score of 7.6 indicates a high impact vulnerability. The EPSS score is < 1%, indicating a very low but nonzero probability of exploitation. The issue is not currently listed in CISA KEV, but the flaw still permits account takeover as soon as an attacker obtains an authenticated session. The attack path requires only legitimate credentials and leverages an unchecked mass assignment route, making exploitation straightforward for anyone who can otherwise access the admin area.
OpenCVE Enrichment
Github GHSA