Files or Directories Accessible to External Parties in Craft CMS - CVE-2024-52292
Published: November 13, 2024 / Updated: June 16, 2026
Craft CMS
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to files or directories accessible to external parties in the mail notification template functionality when rendering a crafted system notification template that calls the dataUrl function with an absolute file path. A remote user can modify a system notification template and trigger a corresponding system email to disclose sensitive information.
Exploitation requires write access to system notification templates and the ability to trigger the related notification email.