Remote Code Execution Vulnerability in Craft CMS by Craft CMS
CVE-2024-52293
What is CVE-2024-52293?
Craft CMS versions prior to 4.12.2 and 5.4.3 are susceptible to a vulnerability that allows for remote code execution on the server. The flaw arises from the absence of a normalizePath function in FileHelper::absolutePath, which can be exploited via Server-Side Template Injection (SSTI) using twig syntax. This issue represents a continuation of the vulnerabilities identified in previous CVE-2023-40035 version. The identified versions containing this vulnerability must be updated to ensure protection against potential exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
EPSS Score
17% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
