Main
Vulnerability Database
Exploits
ID:11112 - Exploit for Exposed dangerous method or function in Craft CMS - CVE-2024-56145
ID:11112 - Exploit for Exposed dangerous method or function in Craft CMS - CVE-2024-56145
Published: February 7, 2025
Vulnerability identifier: #VU101835
Vulnerability risk: High
CVE-ID: CVE-2024-56145
CWE-ID: CWE-749
Exploitation vector: Remote access
Vulnerable software:
Craft CMS
Craft CMS
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to execute arbitrary PHP code on the system.
The vulnerability exists due to usage of unsafe code on systems with enabled register_argc_argv PHP option. A remote attacker can send a specially crafted HTTP request to the application and execute arbitrary PHP code on the system.
Remediation
Install updates from vendor's website.