Description Craft CMS 是一套内容管理系统。2023年9月,官方发布安全公告,披露 CVE-2023-41892 前台远程代码执行漏洞,攻击者可构造恶意请求执行任意代码,控制服务器。
References https://github.com/0day404/HV-2024-POC/blob/main/Craft%20CMS%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9ECVE-2023-41892.md https://cloud.tencent.com/developer/article/2549735 https://inc.xmu.edu.cn/info/1041/8171.htm https://stack.chaitin.com/vuldb/detail/92cdc2ed-2e8a-4632-9782-3dd8561259bd https://www.tenablecloud.cn/plugins/was/114614 https://github.com/Threekiii/Vulnerability-Wiki/blob/master/docs-base/docs/cms/CraftCMS-register_argc_argv-%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E-CVE-2024-56145.md https://nvd.nist.gov/vuln/detail/CVE-2025-23209 https://www.exploit-db.com/exploits/51918 https://craftcms.com/knowledge-base/craft-cms-cve-2025-32432 https://www.assetnote.io/resources/research/how-an-obscure-php-footgun-led-to-rce-in-craft-cms/ https://github.com/craftcms/cms/security/advisories/GHSA-2p6p-9rc9-62j9
Related VulnerabilitiesPoCCVE-2026-65442: FormCraft3 <= 3.9.15 - Server-Side Request ForgeryPoCcraftcms-debug-exposure: CraftCMS Debug Methods ExposedPoCcraftcms-install-exposure: Craft CMS Installation Wizard ExposurePoCcraftcms-log-disclosure: Craft CMS - Log File DisclosureCraft CMS register_argc_argv 代码执行漏洞(CVE-2024-56145)qizhi-fortressaircraft-unauthorized: qizhi fortressaircraft unauthorizedCrafterCMS存在XSS漏洞(CVE-2023-4136)PoCCVE-2020-9757: Craft CMS < 3.3.0 - Server-Side Template InjectionPoCCVE-2021-41749: CraftCMS SEOmatic - Server-Side Template InjectionPoCCVE-2022-0591: Formcraft3 <3.8.28 - Server-Side Request ForgeryPoCCVE-2023-4136: CrafterCMS Engine - Cross-Site ScriptingPoCCVE-2023-41892: CraftCMS < 4.4.15 - Unauthenticated Remote Code Execution