PT-2025-26243 · Unknown+1 · Crafter Cms+1
Published
2025-06-19
·
Updated
2026-05-06
·
CVE-2025-6384
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
CrafterCMS versions 4.0.0 through 4.2.2
Description
An issue exists in Crafter Studio of CrafterCMS that allows authenticated developers to execute operating system commands. This is due to improper control of dynamically-managed code resources, specifically a Groovy Sandbox Bypass. By inserting malicious Groovy elements, an attacker can bypass security restrictions and achieve Remote Code Execution (RCE).
Recommendations
Update CrafterCMS to version 4.3.0 or later.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Crafter Cms
Groovy