CyberSec.Space Logo
返回 CVE 浏览器

CVE-2024-56145

🔥 Known Exploited (CISA KEV)CRITICAL
9.3
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2024-12-18
Last Modified2026-06-17
Data SourcesNVDCISA KEV

Vulnerability Description

Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Users of affected versions are affected by this vulnerability if their php.ini configuration has `register_argc_argv` enabled. For these users an unspecified remote code execution vector is present. Users are advised to update to version 3.9.14, 4.13.2, or 5.5.2. Users unable to upgrade should disable `register_argc_argv` to mitigate the issue.

Affected Platforms (CPE)

📦
Craftcms

Craft Cms

>= 3.0.0 and < 3.9.14>= 4.0.0 and < 4.13.2>= 5.0.0 and < 5.5.2

References & Advisories

相关漏洞威胁