CVE-2024-52293 is a Remote Code Execution (RCE) vulnerability affecting Craft CMS versions prior to 4.12.2 and 5.4.3, stemming from a missing normalizePath function that allows for Server-Side Template Injection (SSTI) via Twig. With a CVSS score of 7.2 (HIGH), this vulnerability presents a significant risk, as it can be exploited remotely by highly privileged attackers with low attack complexity, leading to complete compromise of confidentiality, integrity, and availability. While the EPSS score indicates a moderate likelihood of exploitation, there is currently no public exploit code available, nor is there evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
> 4.0.0, < 4.12.2CPE matchmatch criteria | cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:* | ||
> 5.0.0, < 5.4.3CPE matchmatch criteria | cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:* | ||
4.0.0CPE matchmatch criteria | cpe:2.3:a:craftcms:craft_cms:4.0.0:rc1:*:*:*:*:*:* | ||
4.0.0CPE matchmatch criteria | cpe:2.3:a:craftcms:craft_cms:4.0.0:rc2:*:*:*:*:*:* | ||
4.0.0CPE matchmatch criteria | cpe:2.3:a:craftcms:craft_cms:4.0.0:rc3:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.