CVE-2020-25802: Authenticated attackers with developer privileges in Crafter Studio may execute OS commands via Groovy scripting.
Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via Groovy scripting. This issue affects: Crafter Software Crafter CMS 3.0 versions prior to 3.0.27; 3.1 versions prior to 3.1.7.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-25802?
CVE-2020-25802 is an improper control of dynamically-managed code resources vulnerability in Crafter Studio of Crafter CMS.
How does CVE-2020-25802 affect Crafter Studio?
CVE-2020-25802 allows authenticated developers to execute OS commands via Groovy scripting in Crafter Studio.
What versions of Crafter CMS are affected by CVE-2020-25802?
Crafter CMS 3.0 versions prior to 3.0.27 and 3.1 versions prior to 3.1.7 are affected by CVE-2020-25802.
What is the severity of CVE-2020-25802?
CVE-2020-25802 has a severity rating of 7.2 (critical).
How can I fix CVE-2020-25802 in Crafter Studio?
To fix CVE-2020-25802 in Crafter Studio, upgrade to Crafter CMS version 3.0.27 or 3.1.7.