Horizon Alert
Summary of the vulnerability and why it matters
A flaw in Craft CMS allows unauthorized individuals to gain administrator privileges by exploiting a weakness in user registration, potentially leading to the inheritance of administrative rights from deactivated accounts. This issue arises when public registration is enabled and email verification is disabled, creating a pathway for malicious actors to assume control.
- Issue: Users can gain admin access through registration.
- Why remember: It bypasses standard security controls.
- Executive takeaway: Confirm relevance and understand exposure.
Attack Path
How an attacker could exploit the issue
Attackers can register a new user account by leveraging a flaw in how administrator privileges are handled during user registration. If public registration is enabled and email verification is turned off, an attacker can use the email address of a deactivated administrator to create an account. This inherited administrator status allows the attacker to gain high-level access to the system.
- Public registration and disabled email verification required.
- Registering with a deactivated admin's email.
- Inherit administrator privileges.
Live Threat
Current exploitation, exposure, and threat context
When public registration is enabled and email verification is disabled, an attacker could register using a deactivated administrator's email address. This would allow them to inherit administrator privileges, potentially impacting the integrity and availability of the affected system.
- Administrator privileges could be gained.
- Registration with deactivated admin emails.
- System integrity and availability compromised.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability in Craft CMS could impact organizations using the platform for public-facing websites, particularly if public registration and disabled email verification are enabled. Platform or application owners should first identify all instances of the affected Craft CMS version, confirm their public accessibility and business criticality, and then coordinate with infrastructure and security teams to plan remediation during the next maintenance window.
- Platform or application owners should own the issue.
- Verify public registration and email verification settings.
- Plan remediation during the next maintenance window.