Improper Control of Dynamically-Managed Code Resources in Crafter Studio

CVE Details

Basic Information

Title Improper Control of Dynamically-Managed Code Resources in Crafter Studio
Type cve
Published 2025-06-19T20:57:04.714Z
Last Seen

Product Information

Vendor CrafterCMS
Product CrafterCMS
Version 4.0.0

CVSS Information

Base Score 7.3 (HIGH)
Attack Vector CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:L/VI:H/VA:H/SC:H/SI:H/SA:H
Confidentiality Impact
Integrity Impact
Availability Impact

AI Analysis

AI Description A vulnerability in Crafter Studio allows authenticated developers to bypass Groovy Sandbox restrictions, enabling remote code execution by inserting malicious elements. This affects CrafterCMS versions 4.0.0 through 4.2.2.
AI Severity High
Vendor CrafterCMS
Product Crafter Studio
Affected Version 4.0.0, 4.1.0, 4.2.0, 4.2.1, 4.2.2

Affected Products

  • CrafterCMS CrafterCMS 4.0.0

Additional Information

CVE List
CWE List CWE-913
Bulletin Family

Description

Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of CrafterCMS allows authenticated developers to execute OS commands via Groovy Sandbox Bypass.

By inserting malicious Groovy elements, an attacker may bypass Sandbox restrictions and obtain RCE (Remote Code Execution).

This issue affects CrafterCMS: from 4.0.0 through 4.2.2.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.