CVE-2025-6384

Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of CrafterCMS allows authenticated developers to execute OS commands via Groovy Sandbox Bypass. By inserting malicious Groovy elements, an attacker may bypass Sandbox restrictions and obtain RCE (Remote Code Execution). This issue affects CrafterCMS: from 4.0.0 through 4.2.2.
CVSS

No CVSS.

Configurations

No configuration.

History

23 Jun 2025, 20:16

Type Values Removed Values Added
Summary
  • (es) La vulnerabilidad de control inadecuado de recursos de código gestionados dinámicamente en Crafter Studio de CrafterCMS permite a los desarrolladores autenticados ejecutar comandos del sistema operativo mediante Groovy Sandbox Bypass. Al insertar elementos maliciosos de Groovy, un atacante puede eludir las restricciones de la Sandbox y obtener RCE (ejecución remota de código). Este problema afecta a CrafterCMS desde la versión 4.0.0 hasta la 4.2.2.

19 Jun 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-19 21:15

Updated : 2025-06-23 20:16


NVD link : CVE-2025-6384

Mitre link : CVE-2025-6384

CVE.ORG link : CVE-2025-6384


JSON object : View

Products Affected

No product.

CWE
CWE-913

Improper Control of Dynamically-Managed Code Resources