CraftCMS是CraftCMS公司的一个内容管理系统。 CraftCMS 3.0.0-RC1至3.9.15之前版本、4.0.0-RC1至4.14.15之前版本和5.0.0-RC1至5.6.17之前版本存在安全漏洞,该漏洞源于可能导致远程代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft is vulnerable to remote code execution. This is a high-impact, low-complexity attack vector. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-32432.yaml | POC Details |
| 2 | CraftCMS RCE Checker (CVE-2025-32432) | https://github.com/Chocapikk/CVE-2025-32432 | POC Details |
| 3 | This repository contains a proof-of-concept exploit script for CVE-2025-32432, a pre-authentication Remote Code Execution (RCE) vulnerability affecting CraftCMS versions 4.x and 5.x. The vulnerability exists in the asset transform generation feature of CraftCMS. | https://github.com/Sachinart/CVE-2025-32432 | POC Details |
| 4 | None | https://github.com/CTY-Research-1/CVE-2025-32432-PoC | POC Details |
| 5 | CVE-2025-32432 | https://github.com/B1ack4sh/Blackash-CVE-2025-32432 | POC Details |
| 6 | AI修复生成的CVE-2025-32432的poc | https://github.com/bambooqj/CVE-2025-32432 | POC Details |
| 7 | CVE-2025-32432 | https://github.com/Ashwesker/Blackash-CVE-2025-32432 | POC Details |
| 8 | None | https://github.com/Threekiii/Awesome-POC/blob/master/CMS%E6%BC%8F%E6%B4%9E/Craft%20CMS%20generate-transform%20%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E%20CVE-2025-32432.md | POC Details |
| 9 | https://github.com/vulhub/vulhub/blob/master/craftcms/CVE-2025-32432/README.md | POC Details | |
| 10 | CVE-2025-32432 | https://github.com/Ashwesker/Ashwesker-CVE-2025-32432 | POC Details |
VULNERABLE: RCE confirmed - proof token PROOF_f0daf6ebecf83f07 exfiltrated to /exploit_out.txt
No comments yet