CrafterCMS
cpe:2.3:a:craftercms:craftercms:*:*:*:*:*:*:*
- >= 4.0, < 4.3.0
A remote code execution vulnerability has been identified in Crafter Studio of CrafterCMS versions 4.0.0 prior to 4.2.2. This vulnerability arises from an improper control of dynamically-managed code resources, allowing authenticated developers to execute operating system commands by bypassing Groovy Sandbox restrictions. By inserting malicious Groovy elements, an attacker can exploit this issue to gain remote code execution.
Exploitation of this vulnerability allows for remote code execution on the server where CrafterCMS is running.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.