Description
Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 3.0.0 through 4.16.16, unauthenticated users can trigger database backup operations via specific admin actions, potentially leading to resource exhaustion or information disclosure. Users should update to the patched versions (5.8.21 and 4.16.17) to mitigate the issue. Craft 3 users should update to the latest Craft 4 and 5 releases, which include the fixes.
Remediation
References
Related Vulnerabilities
Atlassian Jira URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2019-11585)
Liferay DXP Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2025-62244)
WordPress Plugin WooCommerce Arbitrary File Download (3.4.5)
Joomla Improper Input Validation Vulnerability (CVE-2015-8564)