Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7c58-g782-9j38

Опубликовано: 05 мая 2025
Источник: github
Github: Прошло ревью
CVSS4: 7.3

Описание

Craft CMS Contains a Potential Remote Code Execution Vulnerability via Twig SSTI

Craft CMS contains a potential remote code execution vulnerability via Twig SSTI. You must have administrator access and ALLOW_ADMIN_CHANGES must be enabled for this to work.

https://craftcms.com/knowledge-base/securing-craft#set-allowAdminChanges-to-false-in-production

Note: This is a follow-up to https://github.com/craftcms/cms/security/advisories/GHSA-f3cw-hg6r-chfv

Users should update to the patched versions (4.14.13 and 5.6.15) to mitigate the issue.

References

https://github.com/craftcms/cms/pull/17026

Пакеты

Наименование

craftcms/cms

composer
Затронутые версииВерсия исправления

>= 4.0.0-RC1, <= 4.14.12

4.14.13

Наименование

craftcms/cms

composer
Затронутые версииВерсия исправления

>= 5.0.0-RC1, <= 5.6.14

5.6.15

EPSS

Процентиль: 49%
0.00257
Низкий

7.3 High

CVSS4

Дефекты

CWE-1336

Связанные уязвимости

CVSS3: 7.2
nvd
9 месяцев назад

Craft is a content management system. Versions of Craft CMS on the 4.x branch prior to 4.14.13 and on the 5.x branch prior to 5.6.16 contains a potential remote code execution vulnerability via Twig SSTI. One must have administrator access and `ALLOW_ADMIN_CHANGES` must be enabled for this to work. Users should update to the patched versions 4.14.13 or 5.6.15 to mitigate the issue.

EPSS

Процентиль: 49%
0.00257
Низкий

7.3 High

CVSS4

Дефекты

CWE-1336