| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-33m5-hqp9-97pw | Craft CMS's Missing Volume Permission Check in AssetsController::actionShowInFolder Allows Information Disclosure |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 13 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 13 May 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Craftcms
Craftcms craftcms |
|
| Vendors & Products |
Craftcms
Craftcms craftcms |
Tue, 12 May 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Craft CMS is a content management system (CMS). From 5.0.0-RC1 to before 5.9.18, AssetsController::actionShowInFolder() fetches an asset by ID and returns its filename and complete folder hierarchy (including volume handle, volume UID, folder names, folder UIDs, and folder URI paths) without checking whether the requesting user has viewAssets or viewPeerAssets permission on the asset’s volume. Any authenticated CP user — even one with zero volume permissions — can enumerate asset filenames and the full folder structure of any volume by supplying arbitrary asset IDs. This vulnerability is fixed in 5.9.18. | |
| Title | Craft CMS: Missing Volume Permission Check in AssetsController::actionShowInFolder Allows Information Disclosure | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-13T14:49:47.308Z
Reserved: 2026-05-04T21:24:36.505Z
Link: CVE-2026-44012
Updated: 2026-05-13T14:49:43.817Z
Status : Deferred
Published: 2026-05-12T21:16:16.003
Modified: 2026-05-13T14:54:50.290
Link: CVE-2026-44012
No data.
OpenCVE Enrichment
Updated: 2026-05-13T09:45:09Z
Github GHSA