Critical remote code execution vulnerability in Craft CMS affecting all versions since 3.0.0 when PHP register_argc_argv is enabled. This vulnerability allows unauthenticated attackers to execute arbitrary code on vulnerable web servers and is actively exploited in the wild.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2024-12-18
Added to CISA KEV: 2025-06-02 166 DAYS BETWEEN CVE AND KEV
CVE-2024-56145 is a critical Remote Code Execution (RCE) vulnerability affecting Craft CMS [3]. It has been officially recognized as a known exploited vulnerability by CISA [1].
An official website of the United States government Here's how you know ... Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Users of affected versions are affected by this ... Vendor Advisory. https://www.cisa.gov/known-exploited-vulnerabilities-โฆ
Unauthenticated RCE on CraftCMS when PHP `register_argc_argv` config setting is enabled - Chocapikk/CVE-2024-56145. ... CVE-2024-56145: Craft CMS Exploitation Tool ๐จ This tool is designed to exploit a vulnerability in Craft CMS identified by the amazing research team at Assetnote. The issue arises dโฆ
CVE-2024-56145 is a remote code execution vulnerability in Craft CMS. Learn about its impact, affected versions, and mitigation methods. ... CVE-2024-56145 is a remote code execution vulnerability in Craft CMS. Learn about its impact, affected versions, and mitigation methods.
Impact. You are affected if your php.ini configuration has registerargcargv enabled. Patches. Update to 3.9.14, 4.13.2, or 5.5.2. Workarounds.