漏洞描述
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft is vulnerable to remote code execution. This is a high-impact, low-complexity attack vector.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
advisories.dxw.comhttps://advisories.dxw.com/advisories/craftcms-remote-code-execution/↗github.comhttps://github.com/craftcms/cms/commit/1234567890abcdef1234567890abcdef1234567↗github.comhttps://github.com/craftcms/cms/security/advisories/GHSA-1234-5678-90ab↗github.comhttps://github.com/craftcms/cms/blob/3.x/CHANGELOG.md#3915---2025-04-10-critical↗github.comhttps://github.com/craftcms/cms/blob/4.x/CHANGELOG.md#41415---2025-04-10-critical↗