Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Craft CMS Session File Vulnerability Allows Arbitrary Content Execution

Vulnerability

A vulnerability exists in Craft CMS versions prior to 5.7.5 and 4.15.3, where unauthenticated users can store arbitrary content, including PHP code, in session files. These session files are saved on the server and can be accessed and executed, potentially using another vulnerability. The issue arises because Craft CMS does not sanitize return URLs before saving them in session files, allowing users to inject malicious content. This vulnerability could be exploited if an attacker can access the session files, possibly through a different vulnerability.

Impact

Exploitation of this vulnerability could lead to the execution of injected PHP code, with the potential for severe consequences depending on the code executed.

Remediation

Users can upgrade to Craft CMS versions 5.7.5 or 4.15.3 to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
10.0
exploitability
10.0
remediation
7.7
relevance
0.0
threat
8.7
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.