Impact
Craft CMS versions 5.0.0 through 5.10.12 erroneously treat a database connection failure as if the site is not installed, allowing anonymous installer actions to be accessed on an active production instance when PHP is still running but the MySQL endpoint is unavailable. If an attacker has a valid guest session cookie and a matching CSRF token that remain valid during the outage, they can submit a predictable variable name through the install/validate-site action. The action serializes the supplied site name and expands ${NAME} expressions using App::env(), which causes the system to reveal values of Craft‑specific environment variables or other system variables, including the security key, database credentials, or API keys. The vulnerability does not provide a method to trigger the database outage itself; it merely exploits the system’s behavior after an external outage occurs.
Affected Systems
Craft CMS product by Craft CMS. The affected releases are all releases from 5.0.0 up to and including 5.10.12. Users of any of these versions are vulnerable until a later fixed release is applied.
Risk and Exploitability
Likely attack vectors are remote web exploitation by submitting a request to the installer endpoint while an outage is happening and a guest session cookie and CSRF token are still in the attacker’s possession. The CVSS score of 8.2 indicates high severity for confidentiality and integrity. The EPSS score less than 1% suggests a low probability of exploitation at any given moment. The vulnerability is not listed in CISA KEV. Remediation requires an upgrade to 5.10.13 or later.
OpenCVE Enrichment