QID 730924

Date Published: 2023-09-25

QID 730924: Craft CMS Remote Code Execution (RCE) Vulnerability (GHSA-4w8r-3xrw-v25g)

Craft CMS is vulnerable to Remote Code Execution Vulnerability due to unsanitized keys in a configuration array.

Affected Versions:
Craft CMS version 4.0.0-RC1 - 4.4.14

QID Detection Logic(Unauthenticated):
This QID sends a crafted payload to /index.php as a POST request and checks for code execution by running phpinfo command.

Successful exploitation of the vulnerability may result in remote code execution, leading to complete system compromise.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Customers are advised to upgrade to Craft CMS version 4.4.15 or later, for more information please refer to GHSA-4w8r-3xrw-v25g

    CVEs related to QID 730924

    Software Advisories
    Advisory ID Software Component Link
    GHSA-4w8r-3xrw-v25g URL Logo github.com/craftcms/cms/security/advisories/GHSA-4w8r-3xrw-v25g