CVE-2025-0502: Transmission of Private Resources into a New Sphere in Crafter Engine
Published Jan 15, 2025
·Updated
Transmission of Private Resources into a New Sphere ('Resource Leak') vulnerability in CrafterCMS Engine on Linux, MacOS, x86, Windows, 64 bit, ARM allows Directory Indexing, Resource Leak Exposure.This issue affects CrafterCMS: from 4.0.0 before 4.0.8, from 4.1.0 before 4.1.6.
Affected Software
5 affected components
CrafterCMS CrafterCMS>=4.0.0, <4.0.8, >=4.1.0, <4.1.6
All of the following
Any of the following
CrafterCMS CrafterCMS>=4.0.0<4.0.8
Any of the following
Apple macOS
Linux Linux kernel
Microsoft Windows
Event History
Jan 15, 2025
CVE Published
via MITRE·05:47 PM
Data Sourced
via MITRE·05:47 PM
DescriptionWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-0502?
The severity of CVE-2025-0502 has not been explicitly rated, but it involves resource leak exposure and directory indexing risks.
2
How do I fix CVE-2025-0502?
To fix CVE-2025-0502, update CrafterCMS to versions 4.0.8 or 4.1.6 or later.
3
What versions of CrafterCMS are affected by CVE-2025-0502?
CVE-2025-0502 affects CrafterCMS versions from 4.0.0 before 4.0.8 and from 4.1.0 before 4.1.6.
4
What types of vulnerabilities does CVE-2025-0502 include?
CVE-2025-0502 includes a resource leak and potential directory indexing vulnerabilities.
5
What platforms are impacted by CVE-2025-0502?
CVE-2025-0502 affects CrafterCMS on Linux, MacOS, Windows, and ARM architectures.