CVE-2024-52293
13.11.2024, 16:15
Craft is a content management system (CMS). Prior to 4.12.2 and 5.4.3, Craft is missing normalizePath in the function FileHelper::absolutePath could lead to Remote Code Execution on the server via twig SSTI. This is a sequel to CVE-2023-40035. This vulnerability is fixed in 4.12.2 and 5.4.3.
Vendor | Product | Version |
---|---|---|
craftcms | craft_cms | 4.0.0 < 𝑥 < 4.12.2 |
craftcms | craft_cms | 5.0.0 < 𝑥 < 5.4.3 |
craftcms | craft_cms | 4.0.0:rc1 |
craftcms | craft_cms | 4.0.0:rc2 |
craftcms | craft_cms | 4.0.0:rc3 |
craftcms | craft_cms | 5.0.0:rc1 |
𝑥
= Vulnerable software versions