CyberRota Analysis
AI-GeneratedCraft CMS 5.10.13.2 is vulnerable to an authenticated remote code execution flaw that allows any user with basic Control Panel access to execute arbitrary PHP commands through manipulated Twig templates. This vulnerability can lead to severe impacts, including full system command execution under the web server's privileges, making it critical for organizations using this version of Craft CMS to prioritize immediate patching. All users with access to the Control Panel should be alerted to this risk, especially those managing web applications that rely on Craft CMS.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Craft CMS 5.10.13.2 contains an authenticated remote code execution vulnerability in the Control Panel action app/render-components. Any authenticated user with basic Control Panel access can submit request-controlled component classes and property overrides. By first overriding an EntryType object’s uiLabelFormat and then rendering an Entry that resolves the same request-cached entry type, an attacker can cause arbitrary Twig supplied in the request to be evaluated by renderObjectTemplate(). This render path is not sandboxed. A Twig string callable can therefore reach PHP functions such as system(), resulting in operating-system command execution with the privileges of the PHP/web-server process. The issue was reproduced with an active non-admin Craft Team user with no optional permissions enabled. No access to entry-editing, Settings, utility, user-management, project-config, filesystem, Kubernetes, or environment variables was required.