Impact
Backpack:CRUD is a Laravel extension that provides CRUD panels for custom administration tasks. From versions 6.0.0 through 6.8.14 and 7.0.38, the framework’s Update, Delete and Reorder endpoints resolved records using an unscoped model query, ignoring the query clauses added with addClause() or addBaseClause(). As a result, an authenticated user who can determine or guess a primary key belonging to an out‑of‑scope record could modify, delete or reorder that record even though it is protected by tenant, ownership or other row‑level access‑control scopes. The flaw does not grant code execution; it facilitates data tampering, confidentiality loss and privilege escalation across tenant boundaries.
Affected Systems
Vendor: Laravel‑Backpack:CRUD. Vulnerable versions are 6.0.0 through 6.8.14 and 7.0.38. The issue is resolved in 6.8.14 and 7.0.38 and later. Applications that do not rely on CRUD query clauses as an authorization mechanism are not affected by this specific bypass.
Risk and Exploitability
The CVSS score of 7.6 indicates a high‑severity vulnerability that primarily impacts data integrity and confidentiality. The EPSS score is less than 1 %, and the flaw is not listed in the CISA KEV catalog, implying no publicly known exploits yet. Exploitation requires an authenticated session and knowledge of an out‑of‑scope record’s primary key, which limits the risk to users who can obtain such credentials. However, because tenant and ownership boundaries are not respected, an attacker can effectively elevate privileges and compromise data for other tenants.
OpenCVE Enrichment
Github GHSA