Close Menu
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Spanish
What's Hot

Cartoonist Paul Pope is more worried about killer robots than AI plagiarism

Spiders scattered behind M&S and cooperative cyberattacks, with up to $592 million in damages

Top Startups and High-Tech Funding News for the Weekly Ends June 20, 2025

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Spanish
Fyself News
Home » Hackers take advantage of the flaws of important craft CMS. Hundreds of servers could have been compromised
Identity

Hackers take advantage of the flaws of important craft CMS. Hundreds of servers could have been compromised

userBy userApril 28, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

April 28, 2025Ravi LakshmananWeb Application Security/Vulnerabilities

Hackers take advantage of important craft CMS flaws

Threat actors have been observed to exploit two newly disclosed serious security flaws in the zero-day attack craft CMS to compromise servers and gain unauthorized access.

The attacks first observed by Orange Cyber ​​Defense Sense Post on February 14, 2025 involve chasing the following vulnerabilities –

CVE-2024-58136 (CVSS score: 9.0) – Inappropriate protection of alternative path defects in the YII PHP framework used by the craft CMS that can be used to access restricted features or resources (regression of CVE-2024-4990) CMS (patched with versions 3.9.15, 4.14.15, and 5.6.17)

According to the cybersecurity company, CVE-2025-32432 resides in a built-in image conversion feature that allows site administrators to maintain images in a specific format.

Cybersecurity

“CVE-2025-32432 relies on the fact that unauthorized users can send POST requests to endpoints responsible for image conversion, and the data in the post is interpreted by the server.”

“In version 3.x of Craft CMS, the asset ID is checked before creating a transform object, but in versions 4.x and 5.x, the asset ID is checked later.

Asset ID refers to the way in which document files and media are managed in the context of a Craft CMS, and each asset is given a unique ID.

It is known that the threat actor behind a campaign will perform multiple post requests until a valid asset ID is detected. A Python script is then run to determine if the server is vulnerable, and if so, download the PHP file from the GitHub repository to the server.

“Between February 10th and 11th, the threat actor improved the script by testing FileManager.php’s download to the web server multiple times in a Python script,” the researchers said. “The file FileManager.php was renamed to Autoload_classmap.php on February 12th and was first used on February 14th.”

Hackers take advantage of important craft CMS flaws

Vulnerable Craft CMS Instances by Country

As of April 18, 2025, an estimated 13,000 vulnerable craft CMS instances have been identified, of which nearly 300 have been said to have been compromised.

“If you check your firewall or web server logs and find a suspicious posting request to an action/asset/Generate-Transform Craft Controller endpoint, the site will be scanned at least for this vulnerability, especially using the string__ class in your body,” Craft CMS says in its advice. “This is not a confirmation that your site has been compromised. It’s just been investigated.”

Cybersecurity

If there is evidence of compromise, it is recommended that users update their security keys, rotate their database credentials, and reset their passwords from a wealth of care.

Disclosure is active! The email zero-day stack-based buffer overflow vulnerability (CVE-2025-42599, CVSS score: 9.8) is subjected to aggressive exploitation in cyberattacks targeting Japanese organizations to achieve remote code execution. Fixed in version 6.60.06008562.

“If a remote third party sends a created request, it may be possible to execute arbitrary code or cause a denial of service (DOS),” Qualitia said in the bulletin.

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleManila has denied China and dealt with the “Philippine mission.” South China Sea News
Next Article Russia-Ukraine War: List of Major Events, Day 1,159 | News
user
  • Website

Related Posts

Spiders scattered behind M&S and cooperative cyberattacks, with up to $592 million in damages

June 21, 2025

Qilin ransomware adds “Cole Lawyer” feature that puts pressure on victims for larger ransoms

June 20, 2025

Television in Iranian states hijacked mid-distance broadcasts amid geopolitical tensions. $90 million stolen from Crypto Heist

June 20, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Cartoonist Paul Pope is more worried about killer robots than AI plagiarism

Spiders scattered behind M&S and cooperative cyberattacks, with up to $592 million in damages

Top Startups and High-Tech Funding News for the Weekly Ends June 20, 2025

Harvard International Students: What the Judge’s Judgment Means

Trending Posts

Sana Yousaf, who was the Pakistani Tiktok star shot by gunmen? |Crime News

June 4, 2025

Trump says it’s difficult to make a deal with China’s xi’ amid trade disputes | Donald Trump News

June 4, 2025

Iraq’s Jewish Community Saves Forgotten Shrine Religious News

June 4, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Top Startups and High-Tech Funding News for the Weekly Ends June 20, 2025

Apple is talking to you to win AI startup confusion

Mira Murati’s AI Startup Thinking Machine Lab emerges from stealth at $20 billion seed and $1 billion valuation

Elon Musk’s AI startup Xai will increase bond yields to 12.5% ​​with a $5 billion debt hike due to weak investor demand

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.