以下是对该漏洞描述信息的中文翻译: Craft CMS 版本 4.8.0 至 4.18.5 以及 5.0.0 至 5.10.12 存在一个安全漏洞:在验证带签名的重定向参数时,系统会使用相同的密钥和格式来对攻击者可控的 cookie 进行签名。原因是 HMAC 签名未绑定其用途——Yii 的 是从与签名请求参数所使用的 Craft 派生出来的。 一个经过身份验证、非管理员用户(无需控制面板访问权限)可以通过 端点设置该 cookie,并将签名的数据包移植到重定向参数中。当登录成功时,Craft 验证签名后,会将已认
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-92593 | 8.8 HIGH | Craft CMS 5.10.0 before 5.10.13 Authenticated Remote Code Execution |
| CVE-2026-92594 | 7.5 HIGH | Craft CMS before 5.11.0 Unauthenticated PII Disclosure via GraphQL |
| CVE-2026-92591 | 5.9 MEDIUM | Craft CMS 5.0.0 before 5.10.13 Environment Secret Exposure via Installer |
| CVE-2026-92590 | 5.4 MEDIUM | Craft CMS 5.7.0 before 5.10.13 Stored XSS via Generated Fields |
| CVE-2026-92589 | 4.3 MEDIUM | Craft CMS 5.0.0 before 5.10.13 Broken Access Control via nested-elements/reorder |
No comments yet