Impact
A user with access to the Control Panel, but no other permissions, could cause arbitrary classes to be instantiated on the server by submitting crafted validation rules. Depending on the classes available in the application, this could be used to destroy files on the server or to make outbound network requests from it.
Exploitation requires an authenticated Control Panel session. It is not reachable by unauthenticated visitors or from the frontend.
Patches
This has been fixed in 5.74.5 and 6.35.1.
Impact
A user with access to the Control Panel, but no other permissions, could cause arbitrary classes to be instantiated on the server by submitting crafted validation rules. Depending on the classes available in the application, this could be used to destroy files on the server or to make outbound network requests from it.
Exploitation requires an authenticated Control Panel session. It is not reachable by unauthenticated visitors or from the frontend.
Patches
This has been fixed in 5.74.5 and 6.35.1.