VulnerabilityModified
CVE-2023-41892
Craft CMS is a platform for creating digital experiences.
CRITICAL 9.8EPSS 92.6%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 92.6%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
Craft CMS is a platform for creating digital experiences. This is a high-impact, low-complexity attack vector. Users running Craft installations before 4.4.15 are encouraged to update to at least that version to mitigate the issue. This issue has been fixed in Craft CMS 4.4.15.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 92.55% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- craftcms/craft cms
- Source
- security-advisories@github.com
References
- http://packetstormsecurity.com/files/176303/Craft-CMS-4.4.14-Remote-Code-Execution.html
- https://github.com/craftcms/cms/blob/develop/CHANGELOG.md#4415---2023-07-03-criticalRelease Notes
- https://github.com/craftcms/cms/commit/7359d18d46389ffac86c2af1e0cd59e37c298857Patch
- https://github.com/craftcms/cms/commit/a270b928f3d34ad3bd953b81c304424edd57355ePatch
- https://github.com/craftcms/cms/commit/c0a37e15cc925c473e60e27fe64054993b867ac1Patch
- https://github.com/craftcms/cms/commit/c0a37e15cc925c473e60e27fe64054993b867ac1#diff-47dd43d86f85161944dfcce2e41d31955c4184672d9bd9d82b948c6b01b86476Patch
- https://github.com/craftcms/cms/security/advisories/GHSA-4w8r-3xrw-v25gPatch, Vendor Advisory
- http://packetstormsecurity.com/files/176303/Craft-CMS-4.4.14-Remote-Code-Execution.html
- https://github.com/craftcms/cms/blob/develop/CHANGELOG.md#4415---2023-07-03-criticalRelease Notes
- https://github.com/craftcms/cms/commit/7359d18d46389ffac86c2af1e0cd59e37c298857Patch
- https://github.com/craftcms/cms/commit/a270b928f3d34ad3bd953b81c304424edd57355ePatch
- https://github.com/craftcms/cms/commit/c0a37e15cc925c473e60e27fe64054993b867ac1Patch
- https://github.com/craftcms/cms/commit/c0a37e15cc925c473e60e27fe64054993b867ac1#diff-47dd43d86f85161944dfcce2e41d31955c4184672d9bd9d82b948c6b01b86476Patch
- https://github.com/craftcms/cms/security/advisories/GHSA-4w8r-3xrw-v25gPatch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.