CVE-2024-56145
RCE when PHP `register_argc_argv` config setting is enabled in craftcms/cms
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- December 16, 2024
- Published Date
- December 18, 2024
- Last Updated
- June 06, 2025
- Vendor
- craftcms
- Product
- cms
- Description
- Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Users of affected versions are affected by this vulnerability if their php.ini configuration has `register_argc_argv` enabled. For these users an unspecified remote code execution vector is present. Users are advised to update to version 3.9.14, 4.13.2, or 5.5.2. Users unable to upgrade should disable `register_argc_argv` to mitigate the issue.
- Tags
- Score
- 94.03% (Percentile: 99.88%) as of 2025-06-14
- Exploitation
- active
- Automatable
- Yes
- Technical Impact
- total
CVSS Scores
CVSS v4.0
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS Score
SSVC Information
References
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
TrendMicro | 2025-05-30 00:00:00 UTC |
Recent Mentions
CISA Adds Five Known Exploited Vulnerabilities to Catalog
Source: All CISA Advisories • Published: 2025-06-02 12:00:00 UTC
Scanner Integrations
Scanner | URL | Date Detected |
---|---|---|
Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/craftcms_ftp_template.rb | 2025-04-29 11:01:12 UTC |
Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-56145.yaml | 2025-04-26 00:00:00 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
craftcms_ftp_template
Type: metasploit • Created: Unknown
Sachinart/CVE-2024-56145-craftcms-rce
Type: github • Created: 2024-12-22 11:53:04 UTC • Stars: 2
Chocapikk/CVE-2024-56145
Type: github • Created: 2024-12-20 03:34:01 UTC • Stars: 42
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Detected by Nuclei
-
Detected by Metasploit
-
Used in Earth Lamia APT Campaign
-
Added to KEVIntel