Impact
The flaw allows an authenticated low‑privilege administrator to reassign, detach, nullify, or delete child records that belong to a different parent or tenant by submitting arbitrary child record identifiers to the attachManyRelation operation. This bypasses the intended restriction of modifying only records that belong to the current parent or are permitted by developer‑defined scope, enabling an attacker to violate data isolation and compromise the integrity of unrelated data. The weakness is a Missing Authorization vulnerability (CWE‑862), giving access to cross‑tenant data manipulation that can affect confidentiality, integrity, and availability of the application data.
Affected Systems
Laravel-Backpack:CRUD versions 6.0.0 through 6.8.15 and 7.0.47 are affected. The fix was released in version 6.8.15 and 7.0.47 and later releases. Vendors other than Backpack:CRUD are not listed as affected.
Risk and Exploitability
The CVSS score is 6.5, indicating moderate severity, and the vulnerability is not yet listed in CISA's KEV catalog. The EPSS score is reported as <1%, indicating a very low but nonzero exploitation probability. The attack requires a legitimate authenticated session of a low‑privilege administrator that can edit a parent form exposing the vulnerable multi‑relation field, so the vector is local web application via feasible privilege escalation rather than remote exploitation. The exploit conditions rely solely on the lack of additional application‑level authorization around submitted relation values, making the vulnerability highly actionable within a compromised or weakly secured administrative environment.
OpenCVE Enrichment
Github GHSA