Craft CMS Remote Code Execution vulnerability
100Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 10epss 93%
from disclosure to weapon23 days
Published on NVDSep 13
1st PoC+23d
metasploitSep 13
VulnCheck+215d
exploitation probability
93%top 1% of all CVEs
observed exploitation
yesVulnCheck
13 public exploit(s)
Craft CMS is a platform for creating digital experiences. This is a high-impact, low-complexity attack vector. Users running Craft installations before 4.4.15 are encouraged to update to at least that version to mitigate the issue. This issue has been fixed in Craft CMS 4.4.15.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
Affected products
craftcms · cmspublic PoCs found — 13
githubgithub.com/0xfalafel/CraftCMS_CVE-2023-41892★ 11githubgithub.com/diegaccio/Craft-CMS-Exploit★ 5githubgithub.com/zaenhaxor/CVE-2023-41892★ 3githubgithub.com/acesoyeo/CVE-2023-41892★ 0githubgithub.com/CERTologists/HTTP-Request-for-PHP-object-injection-attack-on-CVE-2023-41892★ 0githubgithub.com/user01-1/CVE-2023-41892_poc★ 0cve_referencepacketstormsecurity.com/files/176303/Craft-CMS-4.4.14-Remote-Code-Execution.htmlunverifiedvulncheckvulncheck.com/xdb/00f5e8095290unverifiedvulncheckvulncheck.com/xdb/434d4fdb9a37unverifiedvulncheckvulncheck.com/xdb/116af6460340unverifiedvulncheckvulncheck.com/xdb/0ffd1a1c086dunverifiedvulncheckvulncheck.com/xdb/f89f1c76302cunverifiedvulncheckvulncheck.com/xdb/4906ff0ba8e8unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://packetstormsecurity.com/files/176303/Craft-CMS-4.4.14-Remote-Code-Execution.htmlhttps://github.com/craftcms/cms/blob/develop/CHANGELOG.md#4415---2023-07-03-criticalhttps://github.com/craftcms/cms/commit/7359d18d46389ffac86c2af1e0cd59e37c298857https://github.com/craftcms/cms/commit/a270b928f3d34ad3bd953b81c304424edd57355ehttps://github.com/craftcms/cms/commit/c0a37e15cc925c473e60e27fe64054993b867ac1https://github.com/craftcms/cms/commit/c0a37e15cc925c473e60e27fe64054993b867ac1#diff-47dd43d86f85161944dfcce2e41d31955c4184672d9bd9d82b948c6b01b86476https://github.com/craftcms/cms/security/advisories/GHSA-4w8r-3xrw-v25g