Crafter CMS
cpe:2.3:a:craftercms:craftercms:*:*:*:*:*:*:*
- >= 4.0, < 4.5.0
A remote code execution vulnerability has been identified in Crafter CMS's Crafter Studio, specifically in versions 4.0 prior to 4.5.0. This vulnerability arises from an improper control of dynamically-managed code resources, allowing authenticated developers to execute operating system commands by bypassing sandbox restrictions in the Groovy environment.
Exploitation of this vulnerability allows for remote code execution on the server where Crafter CMS is running.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.