Severity
Details
- CVSS score
- 7.0
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
- CWE ID
Overview
About vulnerability
Unauthenticated users can trigger database backup operations the updater/backup action, potentially leading to resource exhaustion or information disclosure.
Users should update to the patched versions (5.8.21 and 4.16.17) to mitigate the issue.
Craft 3 users should update to the latest Craft 4 and 5 releases, which include the fixes.
References:
https://github.com/craftcms/cms/commit/f83d4e0c6b906743206b4747db4abf8164b8da39
https://github.com/craftcms/cms/blob/5.x/CHANGELOG.md#5821---2025-12-04
Affected Endpoints
POST /admin/actions/updater/backup(unauthenticated)
Vulnerability Details
Root Cause
All updater/* actions are explicitly configured with anonymous access:
// BaseUpdaterController.php
protected array|bool|int $allowAnonymous = self::ALLOW_ANONYMOUS_LIVE | self::ALLOW_ANONYMOUS_OFFLINE;
Attack Vector
- Send unauthenticated POST request to
/admin/actions/updater/backup - Database backup executes with configured
backupCommand
Details
- Affected product:
- craftcms/cms , craftcms/feed-me
- Affected packages:
- cms @ 3.9.15 (+1 more)