• News/
  • https://www.bleepingcomputer.com/news/security/craft-cms-rce-exploit-chain-used-in-zero-day-attacks-to-steal-data/

Craft CMS RCE exploit chain used in zero-day attacks to steal data

BleepingComputer
·
Lawrence Abrams
·
Published Apr 25, 2025
·
Updated

Two vulnerabilities impacting Craft CMS were chained together in zero-day attacks to breach servers and steal data, with exploitation ongoing, according to CERT Orange Cyberdefense. The vulnerabilities were discovered by Orange Cyberdefense's CSIRT, which was called in to investigate a compromised server. As part of the investigation, they discovered that two zero-day vulnerabilities impacting Craft CMS were exploited to breach the server: According to a report by SensePost, the ethical hacking team of Orange Cyberdefense, the threat actors chained both of these vulnerabilities together to breach servers and upload a PHP file manager. The attack begins with the exploitation of CVE-2025-32432, which allows attackers to send a specially crafted request containing a "return URL" as a parameter that is saved in a PHP session file. This session name is sent to the visitor as part of the response to the HTTP request. The second stage of the attack leveraged a flaw in the Yii framework (CVE-2024-58136), which Craft CMS utilizes. To exploit this flaw, the attacker sent a malicious JSON payload that caused the PHP code in the session file to be executed on the server. This allowed the attacker to install a PHP-based file manager on the server to compromise the system further. Orange told BleepingComputer that they saw additional compromise steps, including additional uploads of backdoors and data exfiltration. More information about this post-exploitation activity will be detailed in...

Read full article

Affected Software

5 affected components
Craft CMS Craft CMS=3.9.15
Craft CMS Craft CMS=4.14.15
Craft CMS Craft CMS=5.6.17
Yii Yii framework=2.0.52
Craft CMS
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article reports on two vulnerabilities in Craft CMS that are being exploited in ongoing zero-day attacks to steal data.

2

What security implications are discussed in the article?

The security implications include the risk of unauthorized data access and breaches on servers using vulnerable versions of Craft CMS.

3

What software versions are specifically affected by the vulnerabilities?

The affected versions of Craft CMS include 3.9.15, 4.14.15, and 5.6.17, along with Yii framework version 2.0.52.

4

Who identified the vulnerabilities that are being exploited?

The vulnerabilities were discovered by CERT Orange Cyberdefense.

5

What measures should users take to protect their systems from these vulnerabilities?

Users should update their Craft CMS installations to the latest versions to mitigate the risks posed by these vulnerabilities.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203