Intel

AIKIDO-2024-10463

craftcms/cms is vulnerable to Remote Code Execution (RCE)

Remote Code Execution (RCE) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Nov 20, 2024

86

High Risk

This Affects:

phpcraftcms/cms
3.0.0 - 3.9.13
Fixed in 3.9.14
4.0.0 - 4.13.1
Fixed in 4.13.2
5.0.0 - 5.5.1
Fixed in 5.5.2
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to Remote Code Execution (RCE) if a malicious configuration is introduced into the bootstrap.php file. This could allow an attacker to execute arbitrary code on the server, posing a significant security risk.

Who does this affect?

You are affected if you are using a version which is within vulnerability ranges

Background info

craftcms/cms is vulnerable to Remote Code Execution (RCE) in versions 3.0.0 - 3.9.13, 4.0.0 - 4.13.1 and 5.0.0 - 5.5.1.

How to fix this

Upgrade the craftcms/cms library to a patch version.