EXPOSURES › CVE-2024-56145
CVE-2024-56145
HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
⚡ RCE
⌖ EXPLOITED IN THE WILD
SHAME 72/100
rceexploited-in-wildunpatched
Craft CMS RCE due to unpatched php.ini configuration
Craft CMS versions are vulnerable to remote code execution if 'register_argc_argv' is enabled in php.ini, allowing attackers to execute arbitrary code.
Shame score — Craft CMS versions with 'register_argc_argv' enabled in php.ini are exploited in the wild for remote code execution.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
PLAYERS IMPLICATED
DESCRIPTION
Craft CMS contains a code injection vulnerability. Users with affected versions are vulnerable to remote code execution if their php.ini configuration has `register_argc_argv` enabled.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.