Description
Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, `pages.access/list` and `files.access/list` permissions are not consistently checked in the Panel and REST API. This issue has been patched in versions 4.9.0 and 5.4.0.
Problem types
CWE-862: Missing Authorization
CWE-863: Incorrect Authorization
Product status
>= 5.0.0, < 5.4.0
References
github.com/.../kirby/security/advisories/GHSA-85x2-r8xv-ww8c
github.com/getkirby/kirby/releases/tag/4.9.0
github.com/getkirby/kirby/releases/tag/5.4.0