First published: Tue Oct 06 2020(Updated: )
Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via Groovy scripting. This issue affects: Crafter Software Crafter CMS 3.0 versions prior to 3.0.27; 3.1 versions prior to 3.1.7.
Credit: security@craftersoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
Craftercms Studio | >=3.0.0<3.0.27 | |
Craftercms Studio | >=3.1.0<3.1.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-25802 is an improper control of dynamically-managed code resources vulnerability in Crafter Studio of Crafter CMS.
CVE-2020-25802 allows authenticated developers to execute OS commands via Groovy scripting in Crafter Studio.
Crafter CMS 3.0 versions prior to 3.0.27 and 3.1 versions prior to 3.1.7 are affected by CVE-2020-25802.
CVE-2020-25802 has a severity rating of 7.2 (critical).
To fix CVE-2020-25802 in Crafter Studio, upgrade to Crafter CMS version 3.0.27 or 3.1.7.