CyberRota Analysis
AI-GeneratedKirby CMS versions prior to 4.9.4 and 5.4.4 are vulnerable due to a flaw in the content.fileRedirects feature, which allows unauthenticated users to access draft files stored in top-level pages without proper access controls. This could lead to unauthorized disclosure of sensitive draft content. Organizations using affected versions of Kirby should prioritize upgrading to the latest versions to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites with content.fileRedirects enabled could redirect unauthenticated clean file URL requests for files stored in top-level draft pages to physical media URLs without checking page access permissions or preview tokens, leading to disclosure of draft file contents. This issue is fixed in versions 4.9.4 and 5.4.4.