CVE-2025-68456

🔴 Łataj teraz

Nieautoryzowani użytkownicy w Craft mogą wywołać operacje kopii zapasowej bazy danych, co prowadzi do wycieków informacji.

CVSS
9.1
EPSS
0.6%
Exploit
poc
Vendor
craftcms
Opis źródłowy (NVD)

Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 3.0.0 through 4.16.16, unauthenticated users can trigger database backup operations via specific admin actions, potentially leading to resource exhaustion or information disclosure. Users should update to the patched versions (5.8.21 and 4.16.17) to mitigate the issue. Craft 3 users should update to the latest Craft 4 and 5 releases, which include the fixes.

dos exploit Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS9.1
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.6%
Opublikowano (NVD)2026-01-05 22:15:52 UTC
Ostatnia modyfikacja (NVD)2026-10-07 10:10:00 UTC
Referencje