Assetnote Researchers Discover Zero-Day (CVE-2024-56145) in Craft CMS

December 21, 2024 12:00 AM AEDT | By EIN Presswire
 Assetnote Researchers Discover Zero-Day (CVE-2024-56145) in Craft CMS
Image source: EIN Presswire

BRISBANE, AUSTRALIA, December 20, 2024 /EINPresswire.com/ -- A critical security vulnerability has been discovered by Assetnote in Craft CMS that could allow unauthenticated attackers to execute arbitrary code on affected systems.

Craft CMS is one of the world's most popular content management systems used by over 150,000 websites globally. The vulnerability affects Craft CMS installations running versions prior to 5.5.2 and 4.13.2 when using PHP's default configuration settings.

On November 19th, Assetnote's security research team responsibly disclosed to the Craft CMS team that installations with PHP's default configuration could allow attackers to execute arbitrary system commands without authentication. This vulnerability was promptly patched by the Craft CMS team within 24 hours of responsible disclosure and has been assigned CVE-2024-56145.

"We perform 0-day research on the third-party products our Attack Surface Management customers rely on as a way to continuously improve our platform’s findings through novel research," said Shubham Shah, CTO and Co-founder at Assetnote. "We appreciate Craft CMS’ shared commitment to our customers and their swift response to the disclosure, as they fixed the issue within the first 24 hours."

Key Points:

● Affects Craft CMS installations running versions prior to 5.5.2 and 4.13.2
● Requires PHP's register_argc_argv setting to be enabled (default configuration)
● Allows unauthenticated remote code execution
● Can be mitigated by upgrading Craft CMS or disabling register_argc_argv
Affected Versions
● Craft CMS versions prior to 5.5.2
● Craft CMS versions prior to 4.13.2

Impact:

The vulnerability allows unauthenticated remote attackers to achieve Remote Code Execution (RCE) by exploiting PHP's register_argc_argv configuration setting in conjunction with Craft CMS's command-line argument handling. Craft CMS is used by over 150,000 websites worldwide, making this a significant security concern for many organizations.

Technical Details:

The vulnerability stems from Craft CMS's handling of command-line arguments in its bootstrap process. When PHP's register_argc_argv setting is enabled (which is the default configuration), attackers can manipulate the application's file path handling by passing specific query parameters. This can be leveraged to execute arbitrary code through template injection.

Customers of Assetnote were responsibly notified of vulnerable Craft CMS instances in their infrastructure through an early warning system in the Assetnote Attack Surface Management platform. They were able to see verified proof of exploitability so they could mitigate the exposure. The technical analysis and detailed vulnerability report are available on Assetnote's research blog.

About Assetnote:

Assetnote provides industry-leading attack surface management and adversarial exposure validation solutions, helping organizations identify and remediate security vulnerabilities before they can be exploited. Through continuous security testing and verification, Assetnote enables organizations to actionably defend their attack surface without noise. Assetnote customers receive security alerts and mitigations at the same time to disclosure to third-party vendors.

Sonia Awan
Outbloom Public Relations
[email protected]
Visit us on social media:
LinkedIn

Legal Disclaimer:

EIN Presswire provides this news content "as is" without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the author above.


Disclaimer

The content, including but not limited to any articles, news, quotes, information, data, text, reports, ratings, opinions, images, photos, graphics, graphs, charts, animations and video (Content) is a service of Kalkine Media Pty Ltd (“Kalkine Media, we or us”), ACN 629 651 672 and is available for personal and non-commercial use only. The principal purpose of the Content is to educate and inform. The Content does not contain or imply any recommendation or opinion intended to influence your financial decisions and must not be relied upon by you as such. Some of the Content on this website may be sponsored/non-sponsored, as applicable, but is NOT a solicitation or recommendation to buy, sell or hold the stocks of the company(s) or engage in any investment activity under discussion. Kalkine Media is neither licensed nor qualified to provide investment advice through this platform. Users should make their own enquiries about any investments and Kalkine Media strongly suggests the users to seek advice from a financial adviser, stockbroker or other professional (including taxation and legal advice), as necessary.
The content published on Kalkine Media also includes feeds sourced from third-party providers. Kalkine does not assert any ownership rights over the content provided by these third-party sources. The inclusion of such feeds on the Website is for informational purposes only. Kalkine does not guarantee the accuracy, completeness, or reliability of the content obtained from third-party feeds. Furthermore, Kalkine Media shall not be held liable for any errors, omissions, or inaccuracies in the content obtained from third-party feeds, nor for any damages or losses arising from the use of such content.
Kalkine Media hereby disclaims any and all the liabilities to any user for any direct, indirect, implied, punitive, special, incidental or other consequential damages arising from any use of the Content on this website, which is provided without warranties. The views expressed in the Content by the guests, if any, are their own and do not necessarily represent the views or opinions of Kalkine Media. Some of the images/music that may be used on this website are copyrighted to their respective owner(s). Kalkine Media does not claim ownership of any of the pictures displayed/music used on this website unless stated otherwise. The images/music that may be used on this website are taken from various sources on the internet, including paid subscriptions or are believed to be in public domain. We have made reasonable efforts to accredit the source wherever it was indicated as or found to be necessary.
This disclaimer is subject to change without notice. Users are advised to review this disclaimer periodically for any updates or modifications.


AU_advertise

Advertise your brand on Kalkine Media

Sponsored Articles


Investing Ideas

Previous Next
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.