PT-2026-24686 · Craft Cms+2 · Cms+2
Neosprings
·
Published
2026-03-11
·
Updated
2026-03-12
·
CVE-2026-31858
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Craft versions prior to 5.9.9
Description
Craft is a content management system (CMS). The
ElementSearchController::actionSearch() API endpoint lacks the unset() protection that was added to ElementIndexesController. This results in a SQL injection issue, specifically affecting parameters like criteria[orderBy]. Any authenticated control panel user can inject arbitrary SQL through criteria[where], criteria[orderBy], or other query properties. This allows for the extraction of the full database contents via boolean-based blind injection.Recommendations
Update to version 5.9.9 to resolve the issue.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cms
Craft Cms
Craftcms/Cms