By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Hackers Exploit Critical Craft CMS Flaws; Hundreds of Servers Likely Compromised
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Hackers Exploit Critical Craft CMS Flaws; Hundreds of Servers Likely Compromised
Tech News

Hackers Exploit Critical Craft CMS Flaws; Hundreds of Servers Likely Compromised

By Viral Trending Content 4 Min Read
Share
SHARE

Apr 28, 2025Ravie LakshmananWeb Application Security / Vulnerability

Hackers Exploit Critical Craft CMS Flaws

Threat actors have been observed exploiting two newly disclosed critical security flaws in Craft CMS in zero-day attacks to breach servers and gain unauthorized access.

The attacks, first observed by Orange Cyberdefense SensePost on February 14, 2025, involve chaining the below vulnerabilities –

  • CVE-2024-58136 (CVSS score: 9.0) – An improper protection of alternate path flaw in the Yii PHP framework used by Craft CMS that could be exploited to access restricted functionality or resources (A regression of CVE-2024-4990)
  • CVE-2025-32432 (CVSS score: 10.0) – A remote code execution (RCE) vulnerability in Craft CMS (Patched in versions 3.9.15, 4.14.15, and 5.6.17)

According to the cybersecurity company, CVE-2025-32432 resides in a built-in image transformation feature that allows site administrators to keep images to a certain format.

Cybersecurity

“CVE-2025-32432 relies on the fact that an unauthenticated user could send a POST request to the endpoint responsible for the image transformation and the data within the POST would be interpreted by the server,” security researcher Nicolas Bourras said.

“In versions 3.x of Craft CMS, the asset ID is checked before the creation of the transformation object whereas in versions 4.x and 5.x, the asset ID is checked after. Thus, for the exploit to function with every version of Craft CMS, the threat actor needs to find a valid asset ID.”

The asset ID, in the context of Craft CMS, refers to the way document files and media are managed, with each asset given a unique ID.

The threat actors behind the campaign have been found to run multiple POST requests until a valid asset ID is discovered, after which a Python script is executed to determine if the server is vulnerable, and if so, download a PHP file on the server from a GitHub repository.

“Between the 10th and the 11th of February, the threat actor improved their scripts by testing the download of filemanager.php to the web server multiple times with a Python script,” the researcher said. “The file filemanager.php was renamed to autoload_classmap.php on the 12th of February and was first used on the 14th of February.”

Hackers Exploit Critical Craft CMS Flaws

Vulnerable Craft CMS Instances by Country

As of April 18, 2025, an estimated 13,000 vulnerable Craft CMS instances have been identified, out of which nearly 300 have been allegedly compromised.

“If you check your firewall logs or web server logs and find suspicious POST requests to the actions/assets/generate-transform Craft controller endpoint, specifically with the string __class in the body, then your site has at least been scanned for this vulnerability,” Craft CMS said in an advisory. “This is not a confirmation that your site has been compromised; it has only been probed.”

Cybersecurity

If there is evidence of compromise, users are advised to refresh security keys, rotate database credentials, reset user passwords out of an abundance of caution, and block malicious requests at the firewall level.

The disclosure comes as an Active! Mail zero-day stack-based buffer overflow vulnerability (CVE-2025-42599, CVSS score: 9.8) has come under active exploitation in cyber attacks targeting organizations in Japan to achieve remote code execution. It has been fixed in version 6.60.06008562.

“If a remote third-party sends a crafted request, it may be possible to execute arbitrary code or cause a denial-of-service (DoS),” Qualitia said in a bulletin.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

1,139 HP: The New Porsche Cayenne Electric is a Monster

Former Revolut executives raise €30M to bring blockchain-based banking app Deblock to Ireland

Hackers Actively Exploiting 7-Zip Symbolic Link–Based RCE Vulnerability (CVE-2025-11001)

What caused the global Cloudflare outage?

This Home Robot Clears Tables and Loads the Dishwasher All by Itself

TAGGED: Craft CMS, Cyber Security, Cybersecurity, Internet, Malware, Patch Management, Remote Code Execution, Vulnerability, Web Application Security, Zero-Day
Share This Article
Facebook Twitter Copy Link
Previous Article 2 Indian Nationals Charged For Robbing Woman In Singapore Hotel
Next Article Gold’s record rally stalls on hopes of easing global trade tensions
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

South Africa deploys 3,500 police and braces for protests ahead of G20 summit
World News
Best 5 crypto presales predicted to lead the next altcoin season
Crypto
S.T.A.L.K.E.R. 2: Heart of Chornobyl on PS5 – 15 Key Details
Gaming News
Nvidia's Jensen Huang needs investors to party like it’s not 1999
Business
Bitfury Says Goodbye To Mining, Hello To A $1 Billion Tech Fund
Crypto
Battlefield 6′s New Map Is So Good I Can’t Stop Playing It
Gaming News
Dozens go on trial over North Macedonia nightclub fire that killed 63
World News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

South Africa deploys 3,500 police and braces for protests ahead of G20 summit

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
South Africa deploys 3,500 police and braces for protests ahead of G20 summit
November 20, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?