CVE-2024-56145
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Users of affected versions are affected by this vulnerability if their php.ini configuration has registerargcargv enabled. For these users an unspecified remote code execution vector is present. Users are advised to update to version 3.9.14, 4.13.2, or 5.5.2. Users unable to upgrade should disable registerargcargv to mitigate the issue.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/56xxx/CVE-2024-56145.json, https://github.com/Chocapikk/CVE-2024-56145, https://github.com/craftcms/cms/commit/82e893fb794d30563da296bca31379c0df0079b3, https://github.com/craftcms/cms/security/advisories/GHSA-2p6p-9rc9-62j9, https://nvd.nist.gov/vuln/detail/CVE-2024-56145, https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-56145
