CVE-2023-40035 Details
Description
Craft is a CMS for creating custom digital experiences on the web and beyond. Bypassing the validatePath function can lead to potential remote code execution. This vulnerability can lead to malicious control of vulnerable systems and data exfiltrations. Although the vulnerability is exploitable only in the authenticated users, configuration with ALLOW_ADMIN_CHANGES=true, there is still a potential security threat (Remote Code Execution). This issue has been patched in version 4.4.15 and version 3.8.15.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 2, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/craftcms/cms/commit/0bd33861abdc60c93209cff03eeee54504d3d3b5 | CVE | Patch |
| https://github.com/craftcms/cms/releases/tag/3.8.15 | CVE | Release Notes |
| https://github.com/craftcms/cms/releases/tag/4.4.15 | CVE | Release Notes |
| https://github.com/craftcms/cms/security/advisories/GHSA-44wr-rmwq-3phw | CVE | ExploitVendor Advisory |
| https://github.com/craftcms/cms/commit/0bd33861abdc60c93209cff03eeee54504d3d3b5 | [email protected] | Patch |
| https://github.com/craftcms/cms/releases/tag/3.8.15 | [email protected] | Release Notes |
| https://github.com/craftcms/cms/releases/tag/4.4.15 | [email protected] | Release Notes |
| https://github.com/craftcms/cms/security/advisories/GHSA-44wr-rmwq-3phw | [email protected] | ExploitVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-74 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| craftcms craft cms | >= 3.0.0, < 3.8.15 >= 4.0.0, < 4.4.15 4.0.0 rc1 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Aug 29, 2023 | Initial Analysis | [email protected] |