{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/cve-2024-45398/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Craft CMS (5.x)","Craft CMS (4.x)"],"_cs_severities":["critical"],"_cs_tags":["privilege-escalation","cms","web-application","authentication-bypass","cve-2024-45398"],"_cs_type":"advisory","_cs_vendors":["Craft CMS"],"content_html":"\u003cp\u003eCraft CMS versions 5.0.0-RC1 through 5.10.7 contain an insecure mass-assignment vulnerability in the user element save mechanism. The vulnerability resides in the \u003ccode\u003eelements/save\u003c/code\u003e action, where the \u003ccode\u003enewPassword\u003c/code\u003e field is processed by the \u003ccode\u003eUserPasswordValidator\u003c/code\u003e without proper scenario-based restrictions.\u003c/p\u003e\n\u003cp\u003eNormally, password changes in Craft CMS are gated by the \u003ccode\u003eusers/set-password\u003c/code\u003e action, which enforces elevated session verification and requires the user to provide their current password. Because the \u003ccode\u003enewPassword\u003c/code\u003e field is mass-assignable during the generic \u003ccode\u003eelements/save\u003c/code\u003e flow, an attacker with at least \u0026quot;Edit users\u0026quot; permissions can bypass these security controls. This flaw allows an authenticated user to change their own password without verification or, more critically, allows a user with \u0026quot;Edit users\u0026quot; access to overwrite the password of any other user, including those with administrative privileges. This vulnerability impacts all installations running Craft CMS 5.x prior to version 5.10.8.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for complete administrative account takeover by any authenticated user assigned the \u0026quot;Edit users\u0026quot; permission. This impacts organizations relying on Craft CMS for content management by enabling unauthorized access to the control panel, potentially leading to unauthorized content modification, data exfiltration, or further system compromise.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all Craft CMS installations to version 5.10.8 or later immediately to apply the patch for the insecure mass-assignment of the \u003ccode\u003enewPassword\u003c/code\u003e field.\u003c/li\u003e\n\u003cli\u003eAudit the \u0026quot;Edit users\u0026quot; permission across all user accounts in the Craft CMS control panel to identify and revoke the privilege from any account that does not explicitly require it.\u003c/li\u003e\n\u003cli\u003eReview access logs for the \u003ccode\u003eelements/save\u003c/code\u003e endpoint to identify potential abuse by users with \u0026quot;Edit users\u0026quot; privileges.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-07T15:30:17Z","date_published":"2026-08-06T21:29:10Z","id":"https://feed.craftedsignal.io/briefs/2026-08-craft-cms-password-reset/","summary":"An insecure mass-assignment vulnerability in the Craft CMS user element save action allows authenticated users with specific permissions to modify passwords without requiring the current password or elevated verification.","title":"Arbitrary Password Reset Vulnerability in Craft CMS","url":"https://feed.craftedsignal.io/briefs/2026-08-craft-cms-password-reset/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2024-45398","version":"https://jsonfeed.org/version/1.1"}