CVE-2025-68456
🔴 Łataj teraz
Nieautoryzowani użytkownicy w Craft mogą wywołać operacje kopii zapasowej bazy danych, co prowadzi do wycieków informacji.
CVSS
9.1
EPSS
0.6%
Exploit
poc
Vendor
craftcms
Opis źródłowy (NVD)
Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 3.0.0 through 4.16.16, unauthenticated users can trigger database backup operations via specific admin actions, potentially leading to resource exhaustion or information disclosure. Users should update to the patched versions (5.8.21 and 4.16.17) to mitigate the issue. Craft 3 users should update to the latest Craft 4 and 5 releases, which include the fixes.
dos exploit
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 9.1 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.6% |
| Opublikowano (NVD) | 2026-01-05 22:15:52 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-07 10:10:00 UTC |
Referencje
- https://github.com/craftcms/cms/blob/5.x/CHANGELOG.md#5821---2025-12-04 ([email protected]) [Product, Release Notes]
- https://github.com/craftcms/cms/commit/f83d4e0c6b906743206b4747db4abf8164b8da39 ([email protected]) [Patch]
- https://github.com/craftcms/cms/security/advisories/GHSA-v64r-7wg9-23pr ([email protected]) [Exploit, Vendor Advisory]