Craft CMS RCE exploit chain used in zero-day attacks to steal data
ID: 1da18b93-1ed9-5353-89dd-7674435cc682
STIX ID: report--1da18b93-1ed9-5353-89dd-7674435cc682
Feed Name: Bleeping Computer
Two zero-day vulnerabilities in Craft CMS were chained in active attacks: CVE-2025-32432 (an RCE in Craft CMS) was used to store a malicious "return URL" in a PHP session file, and CVE-2024-58136 (an input validation flaw in the Yii framework) allowed execution of PHP code from that session to install a PHP-based file manager. Orange Cyberdefense observed subsequent uploads of backdoors and data exfiltration; patches for Yii and Craft CMS were released and SensePost published IoCs and a full investigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
