Craft CMS External Control of Assumed-Immutable Web Parameter Vulnerability
On Track
Craft CMS / Craft CMS
CWE-472
Description
Craft CMS contains an external control of assumed-immutable web parameter vulnerability. This vulnerability could allow an unauthenticated client to introduce arbitrary values, such as PHP code, to a known local file location on the server. This vulnerability could be chained with CVE-2024-58136 as represented by CVE-2025-32432.
Required Action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
References
Additional Information
- Catalog Version
- 2025.06.02
- Catalog Released
- June 2, 2025
- Days Until Due
- 16 days
- Last Updated
- 4 days, 19 hours ago