THREAT OPS › Threat News › [GHSA] GHSA-p8x7-9vfw-p7vc (high) — Craft CMS: Arbitrary user password reset leading to administrator account takeover
[GHSA] GHSA-p8x7-9vfw-p7vc (high) — Craft CMS: Arbitrary user password reset leading to administrator account takeover
GHSA-p8x7-9vfw-p7vc Severity: high CVE: None
Craft CMS: Arbitrary user password reset leading to administrator account takeover
The vulnerability allows any authenticated user to change their own password without providing the current password or having an active elevated session. It also allows the attacker to change other users’ passwords if the attacker’s account has `edit users` permission (
MITRE ATT&CK techniques
- Control PanelT1218.002
Original source: https://github.com/advisories/GHSA-p8x7-9vfw-p7vc