7.2
CVSSv3

CVE-2022-40635

Published: 13/09/2022 Updated: 16/09/2022
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 0

Vulnerability Summary

Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via Groovy Sandbox Bypass.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

craftercms crafter cms

Github Repositories

CVE-2022-40635: Groovy Sandbox Bypass in CrafterCMS

CVE-2022-40635: Groovy Sandbox Bypass in CrafterCMS Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via Groovy Sandbox Bypass Vendor Disclosure: The vendor's disclosure and fix for this vulnerability can be found here Requirements: This vulnerability requires: V