Impact
Craft CMS versions from 5.0.0‑RC1 through 5.10.5 contain an authorization weakness that lets a control‑panel user with only the viewCategories permission manipulate category hierarchies by using the structures/move‑element operation. The control logic incorrectly derives a write guard from a read permission, enabling the user to reorder and re‑parent categories without possessing saveCategories rights. Because category URLs are generated from their position in the hierarchy, an attacker can permanently alter the URLs of categories and all of their descendants, potentially breaking navigation menus and exposing the site to content disruption or unauthorized disclosures when URL rewrites are leveraged.
Affected Systems
The flaw affects Craft CMS product built by craftcms:cms. All releases from 5.0.0‑RC1 up to and including 5.10.5 are vulnerable, while 5.10.6 and later contain the fix.
Risk and Exploitability
The CVSS score of 9.3 classifies the flaw as critical, indicating that an authenticated attacker can gain permanent control over site structure and user experience. The EPSS score is not available, but the absence of a reported public exploit combined with the high CVSS suggests significant risk if the vulnerability is targeted. The flaw is not currently listed in CISA KEV. Exploitation requires an authenticated user with viewCategories access, which is a common permission level, making the attack path realistic for compromised or poorly segregated accounts. Successful exploitation results in integrity and availability impacts through arbitrary URL alteration and potential site defacement.
OpenCVE Enrichment