Craft CMS Vulnerability Affects Users with Disabled Security Feature
CVE-2024-56145
Key Information
- Vendor
- Craft CMS
- Vendor
- CVE Published:
- 18 December 2024
Badges
What is CVE-2024-56145?
CVE-2024-56145 is a vulnerability found in Craft CMS, a popular content management system designed for creating custom digital experiences. This vulnerability specifically affects users who have enabled the register_argc_argv
setting in their php.ini configuration. If exploited, it presents a remote code execution risk, potentially allowing unauthorized individuals to execute arbitrary code on the server. Such an exploit can severely disrupt organizational operations and compromise sensitive data.
Technical Details
Users of Craft CMS are vulnerable to CVE-2024-56145 due to a configuration oversight in the php.ini settings. The problem arises when the register_argc_argv
feature is enabled, as it allows attackers an unspecified route for remote code execution. Affected users are advised to either upgrade to the latest versions of Craft CMS—4.13.2 or 5.5.2—or disable this feature in their php.ini file as an immediate mitigation strategy.
Potential Impact of CVE-2024-56145
-
Remote Code Execution: The vulnerability can allow attackers to remotely execute arbitrary code on the affected server, potentially leading to full system compromise.
-
Data Breaches: Exploitation of this vulnerability may lead to unauthorized access to sensitive data stored on the website, increasing the risk of data theft or leakage.
-
Operational Disruption: Successful attacks exploiting this vulnerability could disrupt the normal operations of the website or application, impacting user experience and potentially leading to revenue loss.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
News Articles
Assetnote Researchers Discover Zero-Day (CVE-2024-56145) in Craft CMS
Assetnote BRISBANE, AUSTRALIA, December 20, 2024 /EINPresswire.com/ -- A critical security vulnerability has been discovered by Assetnote in Craft CMS that could allow unauthenticated attackers to execute arbitrary code on affected systems. Craft CMS is one of the world's most popular content manage...
1 day ago
Assetnote Researchers Discover Zero-Day (CVE-2024-56145) in Craft CMS
Assetnote BRISBANE, AUSTRALIA, December 20, 2024 /EINPresswire.com/ -- A critical security vulnerability has been discovered by Assetnote in Craft CMS that could allow unauthenticated attackers to execute arbitrary code on affected systems. Craft CMS is one of the world's most popular content manage...
1 day ago