Impact
Craft CMS versions before 5.10.12 allow authenticated control‑panel users to inject Yii2 behaviour attachments and event handlers by posting field‑layout tab elements as JSON strings, bypassing the platform’s cleanse validation. The attacker can then trigger arbitrary PHP object instantiation via Craft::createObject(), leading to remote code execution on the web server.
Affected Systems
The vulnerable product is Craft CMS, produced by craftcms. Versions earlier than 5.10.12 are affected and are identified by the CPE string cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*.
Risk and Exploitability
The CVSS score of 8.7 highlights a high severity vulnerability. EPSS information is not available, and the flaw is not listed in the CISA KEV catalogue. Exploitation requires an authenticated control‑panel account with the ability to edit field layouts; the attacker then injects malicious JSON, causing Craft to instantiate arbitrary objects and execute malicious code. The overall risk is moderate to high, especially in environments where control‑panel access is widely distributed.
OpenCVE Enrichment