Remote Code Execution Vulnerability in Craft CMS by Craft CMS
CVE-2024-52293
7.2HIGH
Summary
Craft CMS versions prior to 4.12.2 and 5.4.3 are susceptible to a vulnerability that allows for remote code execution on the server. The flaw arises from the absence of a normalizePath function in FileHelper::absolutePath, which can be exploited via Server-Side Template Injection (SSTI) using twig syntax. This issue represents a continuation of the vulnerabilities identified in previous CVE-2023-40035 version. The identified versions containing this vulnerability must be updated to ensure protection against potential exploitation.
References
CVSS V3.1
Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published