Impact
The vulnerability resides in Craft CMS versions 5.7.0 through 5.10.11, where the AssetsController::actionMoveInfo endpoint does not enforce volume permission checks. Authenticated control panel users can send a POST request to /assets/move-info with arbitrary folder identifiers and obtain the asset count and total storage size for volumes they lack access to, leaking information about content usage and storage distribution.
Affected Systems
The affected product is Craft CMS, and the vulnerability applies to all releases from version 5.7.0 up to, but not including, 5.10.12. Administrators or users with control panel access are the relevant staff who could exploit this flaw.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate risk. Because EPSS is not available, the likelihood of exploitation is unknown, and the vulnerability is not listed in the CISA KEV catalogue. Exploitation requires authenticated control‑panel privileges, and the attacker gains only data disclosure rather than code execution or privilege escalation. Nonetheless, any user with access to the control panel who can submit arbitrary POST requests to the endpoint could abuse the flaw.
OpenCVE Enrichment