An issue was discovered in Craft CMS before 3.6.7. In some circumstances, a potential Remote Code Execution vulnerability existed on sites that did not restrict administrative changes (if an attacker were somehow able to hijack an administrator's session).
{
"unresolved_ranges": [
{
"source": "CPE_RANGE",
"cpes": [
"cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*"
],
"vendor_product": "craftcms:craft_cms",
"extracted_events": [
{
"fixed": "3.6.7"
},
{
"fixed": "3.6.7"
}
]
},
{
"source": "DESCRIPTION",
"extracted_events": [
{
"fixed": "3.6.7"
}
]
}
]
}