menu
techminis

A naukri.com initiative

google-web-stories
source image

Securityaffairs

2w

read

99

img
dot

Image Credit: Securityaffairs

Attackers chained Craft CMS zero-days attacks in the wild

  • Threat actors have exploited two vulnerabilities in Craft CMS to breach servers and steal data.
  • The vulnerabilities, CVE-2025-32432 and CVE-2024-58136, allowed remote code execution and input validation flaws in Craft CMS and the Yii framework.
  • Attackers exploited the first vulnerability to upload a PHP file manager, and then used the second vulnerability to execute PHP code and compromise the server.
  • The vulnerabilities have been fixed, and indicators of compromise have been released by Orange Cyberdefense's CSIRT.

Read Full Article

like

5 Likes

For uninterrupted reading, download the app