Vulnerability Details
Basic Information
| Title | GHSA-F3GW-9WW9-JMC3 Craft CMS Allows Remote Code Execution |
|---|---|
| Type | osv |
| Published | 2025-04-25T15:02:53 |
| Last Seen | 2025-04-25T16:31:46 |
| CVSS Score | 10.0 (CRITICAL) |
CVSS v3 Details
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | NONE |
| Scope | CHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | LOW |
CVE Information
| CVE IDs | CVE-2025-32432 |
|---|---|
| CWE | |
| Bulletin Family | software |
Description
### Impact
This is an additional fix for https://github.com/craftcms/cms/security/advisories/GHSA-4w8r-3xrw-v25g
This is a high-impact, low-complexity attack vector. To mitigate the issue, users running Craft installations before the fixed versions are encouraged to update to at least that version.
### Details
https://craftcms.com/knowledge-base/craft-cms-cve-2025-32432
### References
https://github.com/craftcms/cms/commit/e1c85441fa47eeb7c688c2053f25419bc0547b47
https://github.com/craftcms/cms/blob/3.x/CHANGELOG.md#3915—2025-04-10-critical
https://github.com/craftcms/cms/blob/4.x/CHANGELOG.md#41415—2025-04-10-critical
https://github.com/craftcms/cms/blob/5.x/CHANGELOG.md#5617—2025-04-10-critical
Impact Assessment
| Base Score | 10.0 |
|---|---|
| Severity | CRITICAL |