Impact
The flaw occurs when an authenticated control panel user who can view entries but cannot save them opens another author's entry in read‑only mode. During that session Craft CMS grants a manageNestedElements flag for the entry’s Matrix or Address fields, and the reorder endpoint relies solely on that flag without checking whether the caller holds save permission for the owning element. Consequently, the attacker can send a POST request to actions/nested-elements/reorder, supplying the parameters visible in the page source, and re‑order the target item blocks without having direct edit rights. This results in unauthorized alteration of content ordering, which can misrepresent information or undermine trust in the site’s data.
Affected Systems
Craft CMS versions 5.0.0 through 5.10.12 from the vendor Craft CMS are affected. The flaw is fixed in version 5.10.13 and later.
Risk and Exploitability
The vulnerability scores a moderate 5.3 on CVSS, and its EPSS score is under 1%, indicating a very low likelihood of exploitation in the wild. It is not listed in CISA’s KEV catalog. The attack requires an authenticated user with view permission but lacking save permission, so the risk is contained to sites that grant such limited access. Nevertheless, the possibility of unauthorized content manipulation warrants prompt remediation, especially on high‑profile or publicly‑facing installations.
OpenCVE Enrichment