National Cyber Warfare Foundation (NCWF)

Hackers Exploit Critical Craft CMS Flaws; Hundreds of Servers Likely Compromised


0 user ratings
2025-04-28 07:32:30
milo
Blue Team (CND)
Threat actors have been observed exploiting two newly disclosed critical security flaws in Craft CMS in zero-day attacks to breach servers and gain unauthorized access.
The attacks, first observed by Orange Cyberdefense SensePost on February 14, 2025, involve chaining the below vulnerabilities -

CVE-2024-58136 (CVSS score: 9.0) - An improper protection of alternate path flaw in the Yii PHP



Source: TheHackerNews
Source Link: https://thehackernews.com/2025/04/hackers-exploit-critical-craft-cms.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)



Copyright 2012 through 2025 - National Cyber Warfare Foundation - All rights reserved worldwide.