Impact
Craft CMS versions prior to 5.10.11 contain a broken access control flaw in the element-indexes/save-elements API. The flaw allows a control panel user to modify the sectionId of an entry after the initial authorization check, effectively moving entries into sections that the user is not permitted to edit. This results in unauthorized publishing or relocation of content and can be used to bypass permissions and potentially expose sensitive information or disrupt site operations.
Affected Systems
Craft CMS installations running any version older than 5.10.11 of the core CMS product. The vulnerability is specific to the element-indexes feature, which is provided by the core Craft CMS platform.
Risk and Exploitability
The CVSS score is 5.3, indicating a moderate severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers require only control panel user access and the ability to submit requests to the element-indexes endpoint. From the description, it is inferred that the only prerequisite is limited section permissions; the attacker can relabel entries to sections for which they have no edit rights. The attack vector is a locally authenticated or web‑based CSRF attack with minimal technical skill needed beyond knowledge of element‑indexes URLs.
OpenCVE Enrichment