GHSA-RVMM-V933-JGXQ
Craft CMS: Missing authorization check allows non-admin control panel users access to user registration metrics
Description
`ChartsController::actionGetNewUsersData()` at `/actions/charts/get-new-users-data` is missing a `requirePermission('viewUsers')` authorization check. Any authenticated control panel user, regardless of permissions beyond `accessCp`, can POST to this endpoint to receive time-series user registration counts for the entire site or for an arbitrary user group ID. The `viewUsers` permission is consistently required throughout the control panel before exposing user-related data, but this action enforces only the base `accessCp` check inherited from the framework. Each call returns the total count of users who joined the specified group in the requested period. ## Impact Any control panel user with only `accessCp` permission can obtain the total number of registered users and their registration date distribution across any time window. In installations with multiple editor roles, this allows a low-privilege control panel user to infer user group sizes and registration trends that would normally require the `viewUsers` permission to access. No user PII (name, email, password) is disclosed; only aggregate counts and timestamps are returned. Confidentiality impact is low. No integrity or availability impact.
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
craftcms/cmsBrowse Packagist / craftcms/cms | GitHub Advisory | 4.0.0-RC1 to < 4.18.1 · Fixed in 4.18.1 | affected |
| 5.0.0-RC1 to < 5.10.3 · Fixed in 5.10.3 | affected |