PT-2025-26243 · Unknown+1 · Crafter Cms+1

Published

2025-06-19

·

Updated

2026-05-06

·

CVE-2025-6384

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CrafterCMS versions 4.0.0 through 4.2.2
Description An issue exists in Crafter Studio of CrafterCMS that allows authenticated developers to execute operating system commands. This is due to improper control of dynamically-managed code resources, specifically a Groovy Sandbox Bypass. By inserting malicious Groovy elements, an attacker can bypass security restrictions and achieve Remote Code Execution (RCE).
Recommendations Update CrafterCMS to version 4.3.0 or later.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-6384
GHSA-5644-3VGQ-2PH5

Affected Products

Crafter Cms
Groovy