Description
Acunetix has identified that Craft CMS is vulnerable to remote code execution (RCE) due to the register_argc_argv setting being enabled in the php.ini configuration. This setting allows command-line arguments to be passed to PHP scripts, potentially enabling attackers to execute arbitrary code on the server.
Remediation
Upgrade to the latest version of Craft CMS or disable register_argc_argv
References
Related Vulnerabilities
OpenSSL Out-of-bounds Read Vulnerability (CVE-2004-0112)
Contao Weak Password Recovery Mechanism for Forgotten Password Vulnerability (CVE-2019-10641)
ownCloud Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2020-28644)
Palo Alto PAN-OS Management Interface Auth Bypass (CVE-2024-0012/CVE-2024-9474)
Python Improper Input Validation Vulnerability (CVE-2013-7338)