Impact
Craft CMS versions before 5.10.12 expose a remote code execution flaw in the element-index endpoint. An authenticated content editor can provide a specially crafted "criteria" parameter that instructs the system to instantiate an arbitrary PHP class. The attack path uses the criteria[withTransforms][0][class] value, which is passed to ImageTransforms::normalizeTransform(), and then leverages a PHP gadget chain involving yii\rbac\PhpManager. By pointing the gadget’s itemFile to a request log containing malicious PHP code in the User-Agent header, the attacker can execute arbitrary PHP on the server.
Affected Systems
All installations of Craft CMS whose version is older than 5.10.12 are vulnerable. The affected product is the Craft CMS content management system released by Craft CMS and the vulnerability exists regardless of deployment environment, provided the element-index endpoint is reachable and a content editor account is available.
Risk and Exploitability
Based on the CVSS score of 8.7, the vulnerability is rated as high severity, meaning that exploitation grants an attacker the ability to run arbitrary PHP code on the affected server. The lack of an EPSS score means there is no published data on current exploitation probability, but the remote nature of the attack and the fact that it requires only an authenticated content‑editor account—an account that is common in many deployments—combined with the absence of a KEV listing, indicate that this flaw could be actively abused in the wild. Attackers would issue a network request to the element‑index endpoint supplying a crafted criteria parameter that forces the system to instantiate a user‑supplied PHP class, creating a complete gadget chain that ultimately executes code in the context of the web application. Because the code runs with the privileges of the web server, impact could range from data theft and defacement to full server compromise.
OpenCVE Enrichment