Description
Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.6 and from version 5.0.0-RC1 to before version 5.9.12, a low-privilege user (or an unauthenticated user who has been sent a shared URL) can escalate their privileges to admin by abusing UsersController->actionImpersonateWithToken. This issue has been patched in versions 4.17.6 and 5.9.12.
Remediation
References
Related Vulnerabilities
WordPress Plugin IBS Mappro Arbitrary File Download (0.6)
WordPress Plugin CSV Importer Multiple Unspecified Vulnerabilities (0.3.7)
WordPress Plugin InstaWP Connect-1-click WP Staging & Migration Arbitrary File Upload (0.1.0.38)
Oracle JRE CVE-2013-5851 Vulnerability (CVE-2013-5851)
WordPress Plugin Contact Form Integrated With Google Maps Cross-Site Scripting (2.4)