{"id":"GHSA-4w8r-3xrw-v25g","summary":"Craft CMS Remote Code Execution vulnerability","details":"### Impact\n\nThis is a high-impact, low-complexity attack vector. Users running Craft installations before 4.4.15 are encouraged to update to at least that version to mitigate the issue. \n\n### Mitigations\n\n* This has been fixed in Craft 4.4.15. You should ensure you’re running at least that version.\n* Refresh your security key in case it has already been captured. You can do that by running the `php craft setup/security-key` command and copying the updated `CRAFT_SECURITY_KEY` environment variable to all production environments.\n* If you have any other private keys stored as environment variables (e.g., S3 or Stripe), refresh those as well.\n* Out of an abundance of caution, you may want to force all your users to reset their passwords in case your database was compromised. You can do that by running `php craft resave/users --set passwordResetRequired --to \"fn() =\u003e true\"`.\n\n### References\n\nhttps://github.com/craftcms/cms/commit/c0a37e15cc925c473e60e27fe64054993b867ac1#diff-47dd43d86f85161944dfcce2e41d31955c4184672d9bd9d82b948c6b01b86476\n\nhttps://github.com/craftcms/cms/commit/7359d18d46389ffac86c2af1e0cd59e37c298857\n\nhttps://github.com/craftcms/cms/commit/a270b928f3d34ad3bd953b81c304424edd57355e\n\nhttps://github.com/craftcms/cms/blob/develop/CHANGELOG.md#4415---2023-07-03-critical\n","aliases":["CVE-2023-41892"],"modified":"2026-09-10T03:49:57.778811098Z","published":"2023-09-13T15:44:09Z","database_specific":{"cwe_ids":["CWE-94"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2023-09-13T15:44:09Z","nvd_published_at":"2023-09-13T20:15:08Z"},"references":[{"type":"WEB","url":"https://github.com/craftcms/cms/security/advisories/GHSA-4w8r-3xrw-v25g"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-41892"},{"type":"WEB","url":"https://github.com/craftcms/cms/commit/7359d18d46389ffac86c2af1e0cd59e37c298857"},{"type":"WEB","url":"https://github.com/craftcms/cms/commit/a270b928f3d34ad3bd953b81c304424edd57355e"},{"type":"WEB","url":"https://github.com/craftcms/cms/commit/c0a37e15cc925c473e60e27fe64054993b867ac1"},{"type":"WEB","url":"https://github.com/craftcms/cms/commit/c0a37e15cc925c473e60e27fe64054993b867ac1#diff-47dd43d86f85161944dfcce2e41d31955c4184672d9bd9d82b948c6b01b86476"},{"type":"PACKAGE","url":"https://github.com/craftcms/cms"},{"type":"WEB","url":"https://github.com/craftcms/cms/blob/develop/CHANGELOG.md#4415---2023-07-03-critical"},{"type":"WEB","url":"http://packetstormsecurity.com/files/176303/Craft-CMS-4.4.14-Remote-Code-Execution.html"}],"affected":[{"package":{"name":"craftcms/cms","ecosystem":"Packagist","purl":"pkg:composer/craftcms/cms"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.0.0-RC1"},{"fixed":"4.4.15"}]}],"versions":["4.0.0","4.0.0-RC1","4.0.0-RC2","4.0.0-RC3","4.0.0.1","4.0.1","4.0.2","4.0.3","4.0.4","4.0.5","4.0.5.1","4.0.5.2","4.0.6","4.1.0","4.1.0.1","4.1.0.2","4.1.1","4.1.2","4.1.3","4.1.4","4.1.4.1","4.2.0","4.2.0.1","4.2.0.2","4.2.1","4.2.1.1","4.2.2","4.2.3","4.2.4","4.2.5","4.2.5.1","4.2.5.2","4.2.6","4.2.7","4.2.8","4.3.0","4.3.1","4.3.10","4.3.11","4.3.2","4.3.2.1","4.3.3","4.3.4","4.3.5","4.3.6","4.3.6.1","4.3.7","4.3.7.1","4.3.8","4.3.8.1","4.3.8.2","4.3.9","4.4.0","4.4.0-beta.1","4.4.0-beta.2","4.4.0-beta.3","4.4.0-beta.4","4.4.0-beta.5","4.4.0-beta.6","4.4.0-beta.7","4.4.1","4.4.10","4.4.10.1","4.4.11","4.4.12","4.4.13","4.4.14","4.4.2","4.4.3","4.4.4","4.4.5","4.4.6","4.4.6.1","4.4.7","4.4.7.1","4.4.8","4.4.9"],"database_specific":{"last_known_affected_version_range":"\u003c= 4.4.14","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/09/GHSA-4w8r-3xrw-v25g/GHSA-4w8r-3xrw-v25g.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L"}]}