CVE-2024-37843 Scanner

Targets the GraphQL endpoint to inject malicious SQL queries, enabling attackers to extract or manipulate database contents.

Short Info


Level

Critical

Single Scan

Single Scan

Can be used by

Asset Owner

Estimated Time

10 seconds

Time Interval

1 month 5 hours

Scan only one

Domain, IPv4, Subdomain

Toolbox

Craft CMS is a flexible content management system used by designers, developers, and content creators to build dynamic websites. It offers a customizable platform for managing content efficiently, with plugins and integrations for enhanced functionality. Adopted by agencies and freelancers, Craft CMS handles complex site requirements and supports various content strategies. It is popular in media, publishing, and e-commerce for developing high-caliber websites and applications, catering to both small projects and large enterprise solutions.

CVE-2024-37843 is a critical SQL injection vulnerability in Craft CMS that arises from improper sanitization of user inputs within the GraphQL API. This flaw allows attackers to inject arbitrary SQL commands into database queries, bypassing intended security controls. The vulnerability stems from insufficient validation of parameters passed to GraphQL resolvers, enabling malicious payloads to be executed against the underlying database.

Specifically, the vulnerability targets the GraphQL API endpoint by manipulating query parameters that are directly concatenated into SQL statements. Attackers can craft malicious GraphQL queries containing SQL injection payloads in fields such as filters or arguments. This allows them to execute arbitrary SQL commands, potentially accessing or modifying database records without proper authorization.

If exploited, this vulnerability can lead to unauthorized data exposure, including sensitive user information, credentials, and content. Attackers may also escalate privileges, corrupt data, or perform denial-of-service attacks on the database. The critical CVSS score of 9.8 highlights the severe risk of full system compromise, making immediate remediation essential for all affected Craft CMS installations.

Get started to protecting your digital assets