PT-2023-5849 · Craft Cms · Craft Cms

Zonia3000

·

Publicado

2023-09-13

·

Atualizado

2025-12-26

·

CVE-2023-41892

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Craft CMS versions prior to 4.4.15
Description This is a high-impact, low-complexity attack vector. Craft CMS is a platform for creating digital experiences. The issue is related to improper code generation control, which can allow a remote attacker to execute arbitrary code. About 1,299 results were found using the ZoomEyeDork app:"Craft CMS".
Recommendations To mitigate the issue, update to at least Craft CMS version 4.4.15. Additionally, refresh your security key by running the php craft setup/security-key command and update the CRAFT SECURITY KEY environment variable in all production environments. Consider refreshing other private keys stored as environment variables. As a precaution, force all users to reset their passwords by running php craft resave/users --set passwordResetRequired --to "fn() => true".

Exploit

Correção

Code Injection

Special Elements Injection

Improper Neutralization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-06536
CVE-2023-41892
GHSA-4W8R-3XRW-V25G

Produtos afetados

Craft Cms