Remote Code Execution via unrestricted file extension in Craft CMS
CVE-2023-32679
What is CVE-2023-32679?
Craft CMS, an open-source content management system by Pixel & Tonic, is vulnerable to a Remote Code Execution exploit due to an unrestricted file extension issue. In specific versions, the function responsible for verifying template existence does not adequately check file extensions when the 'name' parameter is provided. This flaw allows an attacker with admin privileges in a development or misconfigured environment to execute arbitrary code on the server, potentially granting access to the host operating system. Users should upgrade to version 4.4.6 or later to mitigate this vulnerability, as there are no known workarounds.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
cms >= 4.0.0, < 4.4.6
References
EPSS Score
25% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
