CyberRota Analysis
AI-GeneratedCraft CMS is vulnerable due to improper handling of siteId in GraphQL entry mutation resolvers, allowing attackers to manipulate entries across unauthorized sites. This flaw enables an authenticated user with access to one site to create, modify, or delete entries in another site, posing a significant risk to data integrity and confidentiality. Organizations using Craft CMS should prioritize addressing this vulnerability to prevent potential exploitation by malicious actors.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Craft CMS GraphQL entry mutation resolvers (saveEntry, deleteEntry) read siteIddirectly from$argumentswithout passing throughArgumentManagerprepareArguments(), which is the function that enforces site-scope filtering via array_intersect against the GraphQL schema’s allowed sites. The query path (ElementResolverprepareElementQuery) correctly calls prepareArguments()`, so queries to unauthorized sites return empty. But mutations bypass this entirely — an attacker with a token scoped to Site A can create, modify, or delete entries in Site B by passing siteId in the mutations argument.