CVE-2023-41892 is a critical remote code execution (RCE) vulnerability affecting Craft CMS installations prior to version 4.4.15. This high-impact, low-complexity flaw allows unauthenticated attackers to execute arbitrary code on affected systems. With a CVSS score of 9.8 and an EPSS score indicating high exploitability, this vulnerability poses a significant risk. Exploit modules are publicly available in Metasploit and Nuclei, and there is community discussion surrounding its exploitability, though no active exploitation in the wild has been confirmed.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.4.0, < 4.4.15CPE matchmatch criteria | cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.