Impact
Craft CMS versions from 4.0.0‑RC1 to 4.18.1 and from 5.0.0‑RC1 to 5.10.5 contain a flaw that lets an authenticated control‑panel user supply a crafted JSON payload in the condition.config field. The payload bypasses the CMS’s JSON cleansing process, allowing Yii behavior or event keys to be interpreted after decoding, which lets the attacker execute arbitrary system commands as the PHP/web user. The weakness is a form of configuration injection, classified as CWE‑915.
Affected Systems
Affected installations are Craft CMS applications released by craftcms, every release from 4.0.0‑RC1 up to 4.18.1 and from 5.0.0‑RC1 up to 5.10.5. The control‑panel element‑search feature in these versions is the attack surface.
Risk and Exploitability
The CVSS score of 8.7 marks this as a high‑severity vulnerability, and while the EPSS score is not available, the lack of KEV inclusion indicates no known active exploitation reported to date. The attack requires that the adversary already have authenticated access to the CMS control panel; after authentication, they can craft a malicious JSON payload to trigger command execution. Thus the risk is confined to attackers who can obtain valid user credentials or compromise an existing user account.
OpenCVE Enrichment