Loading HuntDB...

CVE-2024-56145

UNKNOWN
Published 2024-12-18T20:37:34.301Z
Actions:
No CVSS data available

Description

Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Users of affected versions are affected by this vulnerability if their php.ini configuration has `register_argc_argv` enabled. For these users an unspecified remote code execution vector is present. Users are advised to update to version 3.9.14, 4.13.2, or 5.5.2. Users unable to upgrade should disable `register_argc_argv` to mitigate the issue.

Available Exploits

Craft CMS - Remote Code Execution via Template Path Manipulation

This template identifies a critical Remote Code Execution (RCE) vulnerability in Craft CMS, identified as GHSA-2p6p-9rc9-62j9. The vulnerability exists due to improper handling of the `--templatesPath` query parameter, allowing attackers to execute arbitrary code by referencing malicious Twig templates.

ID: CVE-2024-56145
Author: jackhax Critical

Related News

No news articles found for this CVE.

Affected Products

Known Exploited Vulnerability

This vulnerability is actively being exploited in the wild

View KEV Details

Remediation Status

On Track

Due Date

June 23, 2025 (16 days remaining)

Added to KEV

June 2, 2025

Required Action

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Affected Product

Vendor/Project: Craft CMS
Product: Craft CMS

Ransomware Risk

Known Ransomware Use
KEV Catalog Version: 2025.06.02 Released: June 2, 2025

References

Published: 2024-12-18T20:37:34.301Z
Last Modified: 2025-06-06T03:55:29.268Z
Copied to clipboard!