OSV 1.4.0 · unreviewed · 修改于 2026-09-02 20:31
发布时间
2026-09-02 20:31
GitHub 审查时间
—
NVD 发布时间
2026-09-02 20:17
源文件
advisories/unreviewed/2026/09/GHSA-4qrm-jp7g-x2p5/GHSA-4qrm-jp7g-x2p5.json
Craft CMS before 5.11.0 fails to enforce user-group scope filters on native GraphQL user relations including author, authors, uploader, draftCreator, and revisionCreator fields. Attackers with a scoped GraphQL token can query these relations to read usernames, email addresses, and full names of any content author or uploader including administrators.
该公告没有提供结构化的受影响软件包信息。