{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2023-41892","assignerOrgId":"a0819718-46f1-4df5-94e2-005712e83aaa","state":"PUBLISHED","assignerShortName":"GitHub_M","dateReserved":"2023-09-04T16:31:48.225Z","datePublished":"2023-09-13T19:45:25.736Z","dateUpdated":"2025-02-13T17:09:04.188Z"},"containers":{"cna":{"title":"Craft CMS Remote Code Execution vulnerability","problemTypes":[{"descriptions":[{"cweId":"CWE-94","lang":"en","description":"CWE-94: Improper Control of Generation of Code ('Code Injection')","type":"CWE"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":10,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L","version":"3.1"}}],"references":[{"name":"https://github.com/craftcms/cms/security/advisories/GHSA-4w8r-3xrw-v25g","tags":["x_refsource_CONFIRM"],"url":"https://github.com/craftcms/cms/security/advisories/GHSA-4w8r-3xrw-v25g"},{"name":"https://github.com/craftcms/cms/commit/7359d18d46389ffac86c2af1e0cd59e37c298857","tags":["x_refsource_MISC"],"url":"https://github.com/craftcms/cms/commit/7359d18d46389ffac86c2af1e0cd59e37c298857"},{"name":"https://github.com/craftcms/cms/commit/a270b928f3d34ad3bd953b81c304424edd57355e","tags":["x_refsource_MISC"],"url":"https://github.com/craftcms/cms/commit/a270b928f3d34ad3bd953b81c304424edd57355e"},{"name":"https://github.com/craftcms/cms/commit/c0a37e15cc925c473e60e27fe64054993b867ac1","tags":["x_refsource_MISC"],"url":"https://github.com/craftcms/cms/commit/c0a37e15cc925c473e60e27fe64054993b867ac1"},{"name":"https://github.com/craftcms/cms/commit/c0a37e15cc925c473e60e27fe64054993b867ac1#diff-47dd43d86f85161944dfcce2e41d31955c4184672d9bd9d82b948c6b01b86476","tags":["x_refsource_MISC"],"url":"https://github.com/craftcms/cms/commit/c0a37e15cc925c473e60e27fe64054993b867ac1#diff-47dd43d86f85161944dfcce2e41d31955c4184672d9bd9d82b948c6b01b86476"},{"name":"https://github.com/craftcms/cms/blob/develop/CHANGELOG.md#4415---2023-07-03-critical","tags":["x_refsource_MISC"],"url":"https://github.com/craftcms/cms/blob/develop/CHANGELOG.md#4415---2023-07-03-critical"},{"url":"http://packetstormsecurity.com/files/176303/Craft-CMS-4.4.14-Remote-Code-Execution.html"}],"affected":[{"vendor":"craftcms","product":"cms","versions":[{"version":">= 4.0.0-RC1, <= 4.4.14","status":"affected"}]}],"providerMetadata":{"orgId":"a0819718-46f1-4df5-94e2-005712e83aaa","shortName":"GitHub_M","dateUpdated":"2023-12-22T16:06:18.015Z"},"descriptions":[{"lang":"en","value":"Craft CMS is a platform for creating digital experiences. This is a high-impact, low-complexity attack vector. Users running Craft installations before 4.4.15 are encouraged to update to at least that version to mitigate the issue. This issue has been fixed in Craft CMS 4.4.15."}],"source":{"advisory":"GHSA-4w8r-3xrw-v25g","discovery":"UNKNOWN"}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-02T19:09:49.199Z"},"title":"CVE Program Container","references":[{"name":"https://github.com/craftcms/cms/security/advisories/GHSA-4w8r-3xrw-v25g","tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://github.com/craftcms/cms/security/advisories/GHSA-4w8r-3xrw-v25g"},{"name":"https://github.com/craftcms/cms/commit/7359d18d46389ffac86c2af1e0cd59e37c298857","tags":["x_refsource_MISC","x_transferred"],"url":"https://github.com/craftcms/cms/commit/7359d18d46389ffac86c2af1e0cd59e37c298857"},{"name":"https://github.com/craftcms/cms/commit/a270b928f3d34ad3bd953b81c304424edd57355e","tags":["x_refsource_MISC","x_transferred"],"url":"https://github.com/craftcms/cms/commit/a270b928f3d34ad3bd953b81c304424edd57355e"},{"name":"https://github.com/craftcms/cms/commit/c0a37e15cc925c473e60e27fe64054993b867ac1","tags":["x_refsource_MISC","x_transferred"],"url":"https://github.com/craftcms/cms/commit/c0a37e15cc925c473e60e27fe64054993b867ac1"},{"name":"https://github.com/craftcms/cms/commit/c0a37e15cc925c473e60e27fe64054993b867ac1#diff-47dd43d86f85161944dfcce2e41d31955c4184672d9bd9d82b948c6b01b86476","tags":["x_refsource_MISC","x_transferred"],"url":"https://github.com/craftcms/cms/commit/c0a37e15cc925c473e60e27fe64054993b867ac1#diff-47dd43d86f85161944dfcce2e41d31955c4184672d9bd9d82b948c6b01b86476"},{"name":"https://github.com/craftcms/cms/blob/develop/CHANGELOG.md#4415---2023-07-03-critical","tags":["x_refsource_MISC","x_transferred"],"url":"https://github.com/craftcms/cms/blob/develop/CHANGELOG.md#4415---2023-07-03-critical"},{"url":"http://packetstormsecurity.com/files/176303/Craft-CMS-4.4.14-Remote-Code-Execution.html","tags":["x_transferred"]}]}]}}