CVE-2024-56145 is a critical remote code execution vulnerability affecting Craft CMS versions 3.9.13 and earlier, 4.13.1 and earlier, and 5.5.1 and earlier, specifically when the php.ini configuration has register_argc_argv enabled. This vulnerability carries a CVSS score of 9.8 (CRITICAL) due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability, allowing unauthenticated attackers to execute arbitrary code. It is actively exploited in the wild, with public exploit code available via Metasploit and Nuclei templates, and has garnered significant community discussion and media coverage, including warnings from CISA.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0.0, < 3.9.14CPE matchmatch criteria | cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:* | ||
>= 4.0.0, < 4.13.2CPE matchmatch criteria | cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:* | ||
>= 5.0.0, < 5.5.2CPE matchmatch criteria | cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.