Description

Craft is a content management system (CMS). Prior to 4.12.2 and 5.4.3, Craft is missing normalizePath in the function FileHelper::absolutePath could lead to Remote Code Execution on the server via twig SSTI. This is a sequel to CVE-2023-40035. This vulnerability is fixed in 4.12.2 and 5.4.3.

INFO

Published Date :

2024-11-13T16:04:52.005Z

Last Modified :

2024-11-13T18:56:00.590Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2024-52293 vulnerability.

Vendors Products
Craftcms
  • Craft Cms
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2024-52293.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact