Impact
Craft CMS versions before 5.10.11 allow a non‑administrator who has the administrateUsers permission to generate a password‐reset URL for any administrator account. The password‑reset endpoint accepts the request without verifying the caller’s administrative session, and the subsequent set‑password action only checks the verification code. Consequently, an attacker can set a new password for any admin account, gaining complete control of the control panel and all data it manages.
Affected Systems
The vulnerability affects Craft CMS of the craftcms:cms product line, impacting all releases from 5.0.0‑RC1 up to (but not including) 5.10.11. Users of these versions should verify their current build against the official upgrade path to 5.10.11 or later.
Risk and Exploitability
The CVSS score of 8.7 classifies this as a high‑severity flaw. Exploitation requires the attacker to possess an authenticated account with administrateUsers rights, which may be available to non‑admin users in some CMS deployments. Because the attack vector is limited to intra‑site authenticated users, the community EPSS score is listed as unavailable, but the potential impact of a successful exploit is substantial: full administrative control. The vulnerability is not currently listed in the CISA KEV catalogue, indicating that no widespread public exploits have been reported at this time.
OpenCVE Enrichment