CVE-2024-56145

CRITICALCVSS 9.8/10Actively ExploitedEPSS 97.45%

Last modified

CVE-2024-56145 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Users of affected versions are affected by this vulnerability if their php.ini configuration has `register_argc_argv` enabled. CISA has confirmed active exploitation in the wild. EPSS estimates a 97.45% chance of exploitation in the next 30 days.

Description

Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Users of affected versions are affected by this vulnerability if their php.ini configuration has `register_argc_argv` enabled. For these users an unspecified remote code execution vector is present. Users are advised to update to version 3.9.14, 4.13.2, or 5.5.2. Users unable to upgrade should disable `register_argc_argv` to mitigate the issue.

Metrics

Exploitation Status

This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .

Weakness Enumeration

Affected Software

VendorProductVersions
CraftcmsCraft Cms>= 3.0.0, < 3.9.14
CraftcmsCraft Cms>= 4.0.0, < 4.13.2
CraftcmsCraft Cms>= 5.0.0, < 5.5.2

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2024-56145?
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Users of affected versions are affected by this vulnerability if their php.ini configuration has `register_argc_argv` enabled. For these users an unspecified remote code execution vector is present. Users are advised to update to version 3.9.14, 4.13.2, or 5.5.2. Users unable to upgrade should disable `register_argc_argv` to mitigate the issue.
How severe is CVE-2024-56145?
CVE-2024-56145 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 97.45% probability of exploitation in the next 30 days. This vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog.
How do I fix CVE-2024-56145?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2024

Are you affected by CVE-2024-56145?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST