Craft CMS Remote Code Execution vulnerability
100Vexday Risk Score
Corrige ahora. Ella explotación observada por VulnCheck y tiene exploit funcional público.
ssvc Actcvss 10epss 93%
de la publicación al arma23 días
Publicada en NVD13 sept
1ª PoC+23d
metasploit13 sept
VulnCheck+215d
probabilidad de explotación
93%top 1% de las CVE
explotación observada
síVulnCheck
13 exploit(s) público(s)
Craft CMS is a platform for creating digital experiences. This is a high-impact, low-complexity attack vector. Users running Craft installations before 4.4.15 are encouraged to update to at least that version to mitigate the issue. This issue has been fixed in Craft CMS 4.4.15.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
Productos afectados
craftcms · cmsPoCs públicas encontradas — 13
githubgithub.com/0xfalafel/CraftCMS_CVE-2023-41892★ 11githubgithub.com/diegaccio/Craft-CMS-Exploit★ 5githubgithub.com/zaenhaxor/CVE-2023-41892★ 3githubgithub.com/acesoyeo/CVE-2023-41892★ 0githubgithub.com/CERTologists/HTTP-Request-for-PHP-object-injection-attack-on-CVE-2023-41892★ 0githubgithub.com/user01-1/CVE-2023-41892_poc★ 0cve_referencepacketstormsecurity.com/files/176303/Craft-CMS-4.4.14-Remote-Code-Execution.htmlno verificadovulncheckvulncheck.com/xdb/00f5e8095290no verificadovulncheckvulncheck.com/xdb/434d4fdb9a37no verificadovulncheckvulncheck.com/xdb/116af6460340no verificadovulncheckvulncheck.com/xdb/0ffd1a1c086dno verificadovulncheckvulncheck.com/xdb/f89f1c76302cno verificadovulncheckvulncheck.com/xdb/4906ff0ba8e8no verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
Referencias
http://packetstormsecurity.com/files/176303/Craft-CMS-4.4.14-Remote-Code-Execution.htmlhttps://github.com/craftcms/cms/blob/develop/CHANGELOG.md#4415---2023-07-03-criticalhttps://github.com/craftcms/cms/commit/7359d18d46389ffac86c2af1e0cd59e37c298857https://github.com/craftcms/cms/commit/a270b928f3d34ad3bd953b81c304424edd57355ehttps://github.com/craftcms/cms/commit/c0a37e15cc925c473e60e27fe64054993b867ac1https://github.com/craftcms/cms/commit/c0a37e15cc925c473e60e27fe64054993b867ac1#diff-47dd43d86f85161944dfcce2e41d31955c4184672d9bd9d82b948c6b01b86476https://github.com/craftcms/cms/security/advisories/GHSA-4w8r-3xrw-v25g