Loading HuntDB...

Craft CMS External Control of Assumed-Immutable Web Parameter Vulnerability

Added June 2, 2025 Due June 23, 2025 CVE-2025-35939
On Track Craft CMS / Craft CMS CWE-472

Description

Craft CMS contains an external control of assumed-immutable web parameter vulnerability. This vulnerability could allow an unauthenticated client to introduce arbitrary values, such as PHP code, to a known local file location on the server. This vulnerability could be chained with CVE-2024-58136 as represented by CVE-2025-32432.

Required Action

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

References

Additional Information

Catalog Version
2025.06.02
Catalog Released
June 2, 2025
Days Until Due
16 days
Last Updated
4 days, 19 hours ago