ID:11373 - Exploit for Code Injection in Craft CMS - CVE-2025-46731

 
Main Vulnerability Database Exploits ID:11373 - Exploit for Code Injection in Craft CMS - CVE-2025-46731

ID:11373 - Exploit for Code Injection in Craft CMS - CVE-2025-46731

Published: May 9, 2025


Vulnerability identifier: #VU108656
Vulnerability risk: Low
CVE-ID: CVE-2025-46731
CWE-ID: CWE-94
Exploitation vector: Remote access
Vulnerable software:
Craft CMS

Link to public exploit:


Vulnerability description

The vulnerability allows a remote user to execute arbitrary code on the target system.

The vulnerability exists due to improper input validation when handling Twig templates. A remote privileged user can and execute arbitrary PHP code on the target system.

Note, successful exploitation of the vulnerability requires that ALLOW_ADMIN_CHANGES is enabled.


Remediation

Install updates from vendor's website.