CVE-2025-35939
Craft CMS External Control of Assumed-Immutable Web Parameter Vulnerability
- 대응 우선순위
- 최우선
- CVSS
- 6.9
- EPSS
- 1.12% 백분위 62.1% · 2026.06.27 기준
- CISA KEV
- 등록
- 조치 기한
- 2025.06.23
- 공개일
- 2025.05.08
CISA KEV에 등록된 실제 악용 확인 취약점
Craft CMS stores arbitrary content provided by unauthenticated users in session files. This content could be accessed and executed, possibly using an independent vulnerability. Craft CMS redirects requests that require authentication to the login page and generates a session file on the server at '/var/lib/php/sessions'. Such session files are named 'sess_[session_value]', where '[session_value]' is provided to the client in a 'Set-Cookie' response header. Craft CMS stores the return URL requested by the client without sanitizing parameters. Consequently, an unauthenticated client can intro...
공급사 Craft CMS
제품 Craft CMS
영향 버전 0, < 4.15.3, >= 5.0.0 < 5.7.5
수정 버전 4.15.3, 5.7.5
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
조치 기한: 2025.06.23CVSS 벡터 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE CWE-472
KEV 등록일 2025.06.02
랜섬웨어 캠페인 사용 미확인
CISA 비고 https://github.com/craftcms/cms/pull/17220 ; https://nvd.nist.gov/vuln/detail/CVE-2025-35939
EPSS 데이터 기준일 2026.06.27