Impact
This vulnerability allows any authenticated user to reset their own password without first providing the current password. Additionally, a user who has the Edit users permission, but not the Administrate users permission, can alter other users’ passwords. As a result, an attacker can take over an administrator account or otherwise elevate their privileges. The weakness is a classic case of improper access control (CWE‑285).
Affected Systems
Manufactured by Craft CMS, the vulnerability applies to all releases prior to the security update released in version 5.10.8. Any installation of Craft CMS that has not yet applied that update is potentially exploitable.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, and the EPS score is not available, so the readily exploitable likelihood is unknown but the impact is significant. Because the attack can be performed with any authenticated account that holds the Edit users permission, the barrier to exploitation is low for those users and no elevated session or admin privilege is needed. The vulnerability is not listed in CISA’s KEV catalog, but the combination of high CVSS and the ability to affect administrative credentials makes it a top‑priority concern.
OpenCVE Enrichment