S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-41892 Scanner

Detects 'Remote Code Execution (RCE)' vulnerability in Craft CMS affects v. before 4.4.15.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.3k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-41892
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

Craft CMS is a platform for creating digital experiences. This is a high-impact, low-complexity attack vector. Users running Craft installations before 4.4.15 are encouraged to update to at least that version to mitigate the issue. This issue has been fixed in Craft CMS 4.4.15.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
cmsby craftcms
>= 4.0.0-RC1, <= 4.4.14
Updated Aug 22, 2026View on NVD →
Detail

Craft CMS is a popular platform for creating digital experiences. Its versatility and flexibility have made it a sought-after tool for creating websites, e-commerce stores, and other digital assets. Craft CMS is designed to be intuitive and easy to use, making it accessible to both experienced developers and those new to the world of web development.

CVE-2023-41892 is a critical vulnerability recently discovered in Craft CMS. The vulnerability is due to the platform's inadequate input validation. Attackers can exploit this vulnerability by injecting arbitrary code into the platform, causing it to execute malicious commands. Upon exploitation, the attacker can gain complete control of the target's system, executing arbitrary code at will.

Unchecked, this vulnerability can have far-reaching consequences on users running Craft CMS, leading to significant data breaches and compliance violations. If exploited, the vulnerability can result in the theft of sensitive data, loss of data, and unauthorized access to critical business systems.

The S4E platform provides an in-depth analysis of security risks associated with digital assets, including Craft CMS, enabling enterprises to take proactive steps to prevent data breaches. The platform's pro features provide users with actionable recommendations to mitigate vulnerabilities, ensuring the safety and security of their digital assets.

 

REFERENCES

Solution Advice

Users can protect against this vulnerability by updating their Craft CMS installations to at least version 4.4.15. Additionally, the following precautions can be taken:

  • Ensure that Craft CMS is regularly updated with the latest security patches and updates
  • Use strong passwords and change them regularly
  • Have a robust backup system in place to facilitate easy recovery in case of data loss
  • Use reputable third-party plugins and extensions vetted for security vulnerabilities
  • Leverage security testing services such as The S4E platform

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.