
Cloud Vulnerability DB
A community-led vulnerabilities database
Improper Control of Dynamically-Managed Code Resources vulnerability was discovered in Crafter Studio of Crafter CMS that affects versions 3.1 < 3.1.18. The vulnerability allows authenticated developers to execute OS commands via FreeMarker static methods (Crafter Docs).
The vulnerability is classified as CWE-913: Improper Control of Dynamically-Managed Code Resources. It was assigned a high-risk rating due to the potential for OS command execution through FreeMarker static methods in the Crafter Studio component (Crafter Docs).
When exploited, this vulnerability allows authenticated developers to execute operating system commands on the affected system through FreeMarker static methods, potentially leading to unauthorized system access and control (Crafter Docs).
Users should upgrade to CrafterCMS version 3.1.18 or later to address this vulnerability. The issue has been fixed in the updated version (Crafter Docs).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."