Exploit Report

Computer Security And Bug Information

CVE-2023-41892

CVECVE-2023-41892
CVE Title
Published Date2023-09-13T20:15Z
Modified Date2023-09-19T01:38Z
CWE TypeCWE-94
CVSS 3.xCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
DescriptionCraft CMS is a platform for creating digital experiences. This is a high-impact, low-complexity attack vector. Users running Craft installations before 4.4.15 are encouraged to update to at least that version to mitigate the issue. This issue has been fixed in Craft CMS 4.4.15.
References
By clicking these links you will leave this website. We do not endorse and will not be held accountable for any activity on external sites.
Reference URLhttps://github.com/craftcms/cms/commit/c0a37e15cc925c473e60e27fe64054993b867ac1#diff-47dd43d86f85161944dfcce2e41d31955c4184672d9bd9d82b948c6b01b86476
Reference DescriptionMISC https://github.com/craftcms/cms/commit/c0a37e15cc925c473e60e27fe64054993b867ac1#diff-47dd43d86f85161944dfcce2e41d31955c4184672d9bd9d82b948c6b01b86476
Reference URLhttps://github.com/craftcms/cms/commit/a270b928f3d34ad3bd953b81c304424edd57355e
Reference DescriptionMISC https://github.com/craftcms/cms/commit/a270b928f3d34ad3bd953b81c304424edd57355e
Reference URLhttps://github.com/craftcms/cms/security/advisories/GHSA-4w8r-3xrw-v25g
Reference DescriptionMISC https://github.com/craftcms/cms/security/advisories/GHSA-4w8r-3xrw-v25g
Reference URLhttps://github.com/craftcms/cms/commit/7359d18d46389ffac86c2af1e0cd59e37c298857
Reference DescriptionMISC https://github.com/craftcms/cms/commit/7359d18d46389ffac86c2af1e0cd59e37c298857
Reference URLhttps://github.com/craftcms/cms/blob/develop/CHANGELOG.md#4415---2023-07-03-critical
Reference DescriptionMISC https://github.com/craftcms/cms/blob/develop/CHANGELOG.md#4415---2023-07-03-critical
TagsPatch
Sources NIST MITRE

This site's data is aggregated programmatically and provided "as is" without any representations or warranties, express or implied. Exploit.report is not affiliated with the The MITRE Corporation, U.S. Department of Homeland Security (DHS), Cybersecurity and Infrastructure Security Agency (CISA), or US government in any way. CVE and the CVE logo are registered trademarks of The MITRE Corporation

© 2022 Exploit.Report | Data | Contact | Privacy Policy | Articles