Craft CMS Remote Code Execution vulnerability
Description
Published to the GitHub Advisory Database
Sep 13, 2023
Reviewed
Sep 13, 2023
Published by the National Vulnerability Database
Sep 13, 2023
Last updated
Dec 22, 2023
Impact
This is a high-impact, low-complexity attack vector. Users running Craft installations before 4.4.15 are encouraged to update to at least that version to mitigate the issue.
Mitigations
php craft setup/security-key
command and copying the updatedCRAFT_SECURITY_KEY
environment variable to all production environments.php craft resave/users --set passwordResetRequired --to "fn() => true"
.References
craftcms/cms@c0a37e1#diff-47dd43d86f85161944dfcce2e41d31955c4184672d9bd9d82b948c6b01b86476
craftcms/cms@7359d18
craftcms/cms@a270b92
https://github.com/craftcms/cms/blob/develop/CHANGELOG.md#4415---2023-07-03-critical
References