Craft is a CMS for creating custom digital experiences on the web and beyond. Bypassing the validatePath function can lead to potential remote code execution. This vulnerability can lead to malicious control of vulnerable systems and data exfiltrations. Although the vulnerability is exploitable only in the authenticated users, configuration with ALLOW_ADMIN_CHANGES=true, there is still a potential security threat (Remote Code Execution). This issue has been patched in version 4.4.15 and version 3.8.15.
References
Link | Resource |
---|---|
https://github.com/craftcms/cms/commit/0bd33861abdc60c93209cff03eeee54504d3d3b5 | Patch |
https://github.com/craftcms/cms/releases/tag/3.8.15 | Release Notes |
https://github.com/craftcms/cms/releases/tag/4.4.15 | Release Notes |
https://github.com/craftcms/cms/security/advisories/GHSA-44wr-rmwq-3phw | Exploit Vendor Advisory |
https://github.com/craftcms/cms/commit/0bd33861abdc60c93209cff03eeee54504d3d3b5 | Patch |
https://github.com/craftcms/cms/releases/tag/3.8.15 | Release Notes |
https://github.com/craftcms/cms/releases/tag/4.4.15 | Release Notes |
https://github.com/craftcms/cms/security/advisories/GHSA-44wr-rmwq-3phw | Exploit Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 08:18
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/craftcms/cms/commit/0bd33861abdc60c93209cff03eeee54504d3d3b5 - Patch | |
References | () https://github.com/craftcms/cms/releases/tag/3.8.15 - Release Notes | |
References | () https://github.com/craftcms/cms/releases/tag/4.4.15 - Release Notes | |
References | () https://github.com/craftcms/cms/security/advisories/GHSA-44wr-rmwq-3phw - Exploit, Vendor Advisory |
29 Aug 2023, 15:24
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:craftcms:craft_cms:4.0.0:rc1:*:*:*:*:*:* cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.2 |
First Time |
Craftcms
Craftcms craft Cms |
|
References | (MISC) https://github.com/craftcms/cms/security/advisories/GHSA-44wr-rmwq-3phw - Exploit, Vendor Advisory | |
References | (MISC) https://github.com/craftcms/cms/releases/tag/4.4.15 - Release Notes | |
References | (MISC) https://github.com/craftcms/cms/commit/0bd33861abdc60c93209cff03eeee54504d3d3b5 - Patch | |
References | (MISC) https://github.com/craftcms/cms/releases/tag/3.8.15 - Release Notes |
23 Aug 2023, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-08-23 21:15
Updated : 2024-11-21 08:18
NVD link : CVE-2023-40035
Mitre link : CVE-2023-40035
CVE.ORG link : CVE-2023-40035
JSON object : View
Products Affected
craftcms
- craft_cms
CWE
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')