mediumVulnerability

GHSA-rvmm-v933-jgxq

`ChartsController::actionGetNewUsersData()` at `/actions/charts/get-new-users-data` is missing a `requirePermission('viewUsers')` authorization check. Any authenticated control panel user, regardless of permissions beyond `accessCp`, can POST to this endpoint to receive time-series user registration counts for the entire site or for an arbitrary user group ID. The `viewUsers` permission is consistently required throughout the control panel before exposing user-related data, but this action enforces only the base `accessCp` check inherited from the framework. Each call returns the total count of users who joined the specified group in the requested period. ## Impact Any control panel user with only `accessCp` permission can obtain the total number of registered users and their registration date distribution across any time window. In installations with multiple editor roles, this allows a low-privilege control panel user to infer user group sizes and registration trends that would normally require the `viewUsers` permission to access. No user PII (name, email, password) is disclosed; only aggregate counts and timestamps are returned. Confidentiality impact is low. No integrity or availability impact.

Properties

ghsa_id
GHSA-rvmm-v933-jgxq
severity
medium
summary
Craft CMS: Missing authorization check allows non-admin control panel users access to user registration metrics
cve_id
GHSA-rvmm-v933-jgxq
is_ghsa_only
true
ghsa_published
2026-08-06T21:42:58Z
source_url
https://github.com/advisories/GHSA-rvmm-v933-jgxq
ghsa_updated
2026-08-06T21:42:58Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]composer/craftcms/cms

AFFECTS (1)

[Software]composer/craftcms/cms

HAS_WEAKNESS (1)

[Weakness]Missing Authorization

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph