Remote Code Execution Vulnerability in Craft CMS by Craft CMS
CVE-2024-52293

7.2HIGH

Key Information:

Vendor
Craftcms
Status
Vendor
CVE Published:
13 November 2024

Summary

Craft CMS versions prior to 4.12.2 and 5.4.3 are susceptible to a vulnerability that allows for remote code execution on the server. The flaw arises from the absence of a normalizePath function in FileHelper::absolutePath, which can be exploited via Server-Side Template Injection (SSTI) using twig syntax. This issue represents a continuation of the vulnerabilities identified in previous CVE-2023-40035 version. The identified versions containing this vulnerability must be updated to ensure protection against potential exploitation.

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.