Impact
Craft CMS versions 5.10.0 through 5.10.12 contain an incomplete fix that permits server‑side template injection. An authenticated low‑privilege control panel user who has editing rights on a single element type can craft a self‑signed HMAC token that contains attacker‑controlled Twig code for the returnUrl parameter. The token can be replayed as a redirect POST parameter, reaching an unsandboxed Twig sink in View::renderObjectTemplate() and allowing execution of arbitrary PHP code on the server, effectively giving full server compromise.
Affected Systems
Craft CMS 5.10.0 to 5.10.12 from CraftCMS. The affected versions are those prior to 5.10.13, according to the advisory.
Risk and Exploitability
The CVSS score is 8.7, indicating a high‑severity flaw. The EPSS score is reported as less than 1 %, showing a very low probability of real‑world exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated user with edit permissions on an element type, so attackers must first compromise a legitimate user account with at least that level of access. Once the conditions are met, the attacker can replay the forged HMAC token to trigger the unsandboxed Twig sink and execute code on the server.
OpenCVE Enrichment