Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
🐘 Packagist

GHSA-43cq-c2gq-pfpw

Craft CMS: Authorization bypass in `entries/move-to-section` via missing target-section save check

Also known asCVE-2026-50280
Published
Jul 2, 2026
Updated
Jul 2, 2026
Affected
1 pkg
Patched
1 / 1
Exploits
None indexed

Blast Radius

1 pkg affected
🐘craftcms/cms

Real-time download stats are indexed for npm and PyPI packages. This vulnerability affects Packagist packages — download data is not available via public APIs for these ecosystems.

Description

Summary

The EntriesController::actionMoveToSection() endpoint checks only whether the current user can view the destination section, but it does not require permission to save entries into that section. A low-privileged authenticated control-panel user who can move an entry out of its current section can therefore move that entry into a different section where they have read access but no write access.

Details

The vulnerable route is implemented in EntriesController.php:465:

The destination check is only viewEntries:$section->uid . The source-entry gate is Entry::canMove(), which verifies whether the user can move the existing entry based on the source section:

This closes the exploit chain:

  1. External source: authenticated CP request to entries/move-to-section.
  2. Missing authorization check: destination section requires only viewEntries, not saveEntries.
  3. Privileged sink: moveEntryToSection() rewrites sectionId and saves the entry into the unauthorized section.

Preconditions derived from the code:

  1. The attacker is authenticated to the control panel.
  2. Entry 345 is movable by the attacker from its current section.
  3. The attacker can satisfy viewEntries on destination section 12.
  4. The attacker does not have saveEntries:DESTINATION_UID, which is the missing check that makes the bypass possible.

Result:

  1. The controller accepts the request because viewEntries:$section->uid passes.
  2. Each source entry passes canMove() based on source-section permissions.
  3. moveEntryToSection() updates the entry’s sectionId and saves it.
  4. The entry is now located in a section where the attacker did not have write permission.

Impact

This breaks the intended section-level authorization model. A user with limited content permissions can inject or relocate content into a protected section, interfering with editorial boundaries, approval workflows, section-specific business logic, and content ownership expectations.

Affected Packages

1 total 1 fixed
EcosystemPackageVulnerable rangeFix
🐘Packagistcraftcms/cms5.0.0-RC1&&< 5.9.215.9.21

Detection & mitigation playbook

Open-source dependency
  1. Detect

    Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for craftcms/cms. O3's reachability analysis confirms whether the vulnerable code path is actually invoked in your application, so you act on real exposure instead of every transitive match.

  2. Fix

    Update craftcms/cms to 5.9.21 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms GHSA-43cq-c2gq-pfpw is resolved across your whole dependency graph.

  3. Workarounds

    If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.

  4. How O3 protects you

    O3 pinpoints whether GHSA-43cq-c2gq-pfpw is reachable in your code and exactly where to fix it, then blocks exploitation in production at runtime until the patched version is deployed.

Tailored to GHSA-43cq-c2gq-pfpw. Runtime protection reduces exposure until a permanent patch is applied and verified — it complements patching, it doesn't replace it.

Frequently Asked Questions

### Summary The `EntriesController::actionMoveToSection()` endpoint checks only whether the current user can view the destination section, but it does not require permission to save entries into that section. A low-privileged authenticated control-panel user who can move an entry out of its current section can therefore move that entry into a different section where they have read access but no write access. ### Details The vulnerable route is implemented in [EntriesController.php](/D:/files/projects/cms-5.9.19/cms-5.9.19/src/controllers/EntriesController.php):465: The destination check is
O3 Security · Impact-Aware SCA

Is GHSA-43cq-c2gq-pfpw in your dependencies?

O3 detects GHSA-43cq-c2gq-pfpw across Packagist dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.