Threats Tagged 'ghsa-xxpx-f366-4xpq'
View all threats tagged with 'ghsa-xxpx-f366-4xpq'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'ghsa-xxpx-f366-4xpq'
Click on any threat for detailed analysis and mitigation recommendations
Craft CMS:Authorization bypass: view-only Categories user can modify category structure via structures/move-element 0 Craft CMS contains an authorization bypass vulnerability allowing a user with only viewCategories permission to modify the category structure by reordering and re-parenting categories via the structures/move-element action. This flaw arises because the system trusts a read-time authorization grant for a write operation, permitting unauthorized structural changes to category taxonomies. The issue affects Craft CMS version 5.10.5 and is distinct from previously fixed authorization bypasses. The impact is limited to integrity and broken access control, with no confidentiality or remote code execution implications. Join the discussion | GCVE Database | 08/06/2026, 21:43:54 UTC Added: 08/07/2026, 05:57:13 UTC |
Showing 1 to 1 of 1 result