CVE-2024-52293: Craft CMS vulnerable to Potential Remote Code Execution via missing path normalization & Twig SSTI
Missing normalizePath
in the function FileHelper::absolutePath
could lead to Remote Code Execution on the server via twig SSTI.
(Post-authentication, ALLOW_ADMIN_CHANGES=true)
References
Detect and mitigate CVE-2024-52293 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →