Vulnerability Details
Basic Information
| Title | Craft CMS Allows Remote Code Execution |
|---|---|
| Type | github |
| Published | 2025-04-25T15:02:53 |
| Last Seen | 2025-04-25T16:38:13 |
| CVSS Score | 10.0 (CRITICAL) |
CVSS v3 Details
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | NONE |
| Scope | CHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | LOW |
CVE Information
| CVE IDs | CVE-2025-32432 |
|---|---|
| CWE | CWE-94 |
| Bulletin Family | software |
Description
Impact This is an additional fix for https://github.com/craftcms/cms/security/advisories/GHSA-4w8r-3xrw-v25g This is a high-impact, low-complexity attack vector. To mitigate the issue, users running Craft installations before the fixed versions…
Impact Assessment
| Base Score | 10.0 |
|---|---|
| Severity | CRITICAL |