CVE-2023-41892 is an unauthenticated remote code execution vulnerability in Craft CMS versions earlier than 4.4.15. The flaw permits PHP object injection through attacker-controlled input, enabling execution of attacker-supplied code without prior authentication.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
5 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Repository contains two standalone Python proof-of-concept exploits plus documentation and a Docker lab for CVE-2023-41892, a pre-authenticated RCE in Craft CMS ConditionsController. The repository structure is small and focused: `LFI_to_RCE.py` implements a two-stage exploit that first poisons Craft CMS logs with embedded PHP via malformed JSON, then triggers inclusion of the dated log file using the `craft\elements\conditions\users\UserCondition` + `\Psy\Configuration` gadget chain. `Imagick_PoC.py` implements an alternate exploit path using multipart upload and the `imagick` gadget with `vid:msl:/tmp/php*` to process an uploaded MSL file and write `webshell.php` into the web root, then verifies success by requesting the file and checking for phpinfo output. Both scripts target the same vulnerable endpoint, `/index.php?action=conditions/render`, against a default lab URL of `http://localhost:8088`. The included `Vulnhub_env/docker-compose.yml` provisions a local vulnerable environment using `vulhub/craftcms:4.4.14` and `mysql:5.7`, while the README files document setup, exploitation steps, prerequisites, and troubleshooting. Overall, this is a real exploit repository, not a detector: it demonstrates unauthenticated remote code execution and arbitrary file write against vulnerable Craft CMS versions, with basic hardcoded phpinfo-based payloads suitable for lab reproduction.
This repository provides two Python proof-of-concept exploits for CVE-2023-41892, targeting Craft CMS. The exploits leverage a vulnerability in the 'conditions/render' action to upload a PHP webshell to the server's cpresources directory. The 'poc_noauth.py' script uploads a simple, unauthenticated webshell that allows arbitrary command execution via the 'cmd' GET parameter. The 'poc_auth.py' script uploads a webshell that requires a SHA-256 hashed key for authentication, increasing stealth and limiting access. Both scripts first extract server paths by abusing a PHP object injection to call phpinfo(), then craft and upload a malicious XML payload to write the webshell, and finally attempt to trigger the payload. The README provides detailed usage instructions, including how to set the authentication key for the protected webshell. The main endpoints of interest are the webshell URLs, which allow remote command execution if the exploit is successful. The repository is operational and provides working exploit code, but is not weaponized for mass exploitation.
This repository contains a single Metasploit module (Ruby file) that exploits an unauthenticated remote code execution (RCE) vulnerability (CVE-2023-41892) in Craft CMS versions 4.0.0-RC1 through 4.4.14. The exploit leverages a PHP object injection vulnerability in the ConditionsController class, combined with the Imagick extension and Magick Scripting Language (MSL), to write a malicious PHP webshell to the server's document root. The module supports multiple payloads, including PHP Meterpreter reverse shells, Unix command shells, and Linux droppers, and can clean up artifacts after exploitation. The attack is performed over HTTP(S) and does not require authentication. The module is highly weaponized, providing automated exploitation, payload delivery, and cleanup. The only endpoints referenced are the base URL of the target Craft CMS instance and file paths for the webshell and temporary files. The repository is structured as a typical Metasploit exploit module, with all logic contained in a single Ruby file.
This repository contains a Python exploit script (exploit.py) and a README.md. The exploit targets CVE-2023-41892, a remote code execution vulnerability in Craft CMS versions 4.0.0-RC1 through 4.4.14. The exploit works by abusing a vulnerable endpoint to upload a PHP webshell (notMalicious.php) to the target server. It first discovers the server's document root and temporary upload directory by triggering a phpinfo() leak, then uploads a maliciously crafted file using a POST request. After the webshell is deployed, the script uses it to execute arbitrary commands, specifically a bash reverse shell that connects back to the attacker's machine (whose IP and port are provided as arguments). The README provides usage instructions, including setting up a netcat listener and running the exploit. The main attack vector is network-based, requiring HTTP access to the vulnerable Craft CMS instance. The exploit is operational, providing a working reverse shell payload, and is not part of a larger framework.
This repository contains a Python exploit (craft-cms.py) targeting an unauthenticated remote code execution vulnerability (CVE-2023-41892) in Craft CMS versions 4.0.0-RC1 through 4.4.14. The exploit works by sending specially crafted POST requests to the /index.php endpoint of a vulnerable Craft CMS installation, leveraging a deserialization vulnerability to execute PHP code. It first extracts configuration information from the target using phpinfo(), then uploads a PHP webshell (shell.php) to the web server's document root using an Imagick-based file write trick. Once the webshell is deployed, the script provides an interactive pseudo-shell, allowing the attacker to execute arbitrary commands on the target via HTTP requests to /shell.php. The repository includes a README.md with usage instructions and references, and the main exploit logic is contained in craft-cms.py. No authentication is required, and the exploit is operational, providing a working webshell payload.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unauthenticated remote-code-execution vulnerability in Craft CMS, mentioned only as an alternative Metasploit module during module enumeration.
A previously disclosed Craft CMS vulnerability referenced as the earlier issue for which CVE-2025-32432 provides an additional fix.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.