CVE-2025-35939
MEDIUM CISA KEVDescription
Craft CMS stores arbitrary content provided by unauthenticated users in session files. This content could be accessed and executed, possibly using an independent vulnerability. Craft CMS redirects requests that require authentication to the login page and generates a session file on the server at '/var/lib/php/sessions'. Such session files are named 'sess_[session_value]', where '[session_value]' is provided to the client in a 'Set-Cookie' response header. Craft CMS stores the return URL requested by the client without sanitizing parameters. Consequently, an unauthenticated client can introduce arbitrary values, such as PHP code, to a known local file location on the server. Craft CMS versions 5.7.5 and 4.15.3 have been released to address this issue.
CVSS v3.1 Score
CISA Known Exploited Vulnerability
This vulnerability is actively exploited in the wild.
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| craftcms | craft_cms |
| craftcms | craft_cms |
References
Advisories & Patches
Other References
Frequently Asked Questions
What is CVE-2025-35939? +
How severe is CVE-2025-35939? +
What products are affected by CVE-2025-35939? +
How do I check if I'm vulnerable to CVE-2025-35939? +
Related Vulnerabilities
UsersController::edit in Cerebrate before 1.30 allows an authenticated non-privileged user to escalate their privileges (e.g., obtain a higher role such …
FacturaScripts is an open source accounting and invoicing software. In versions 2025.92 and earlier, the application fails to validate the …
SendQuick Entera devices before 11HF5 are vulnerable to CAPTCHA bypass by removing the Captcha parameter.
A hidden field manipulation vulnerability was identified in Issuetrak version 17.1 that could be triggered by an authenticated user. When …
fblog through 983bede allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset …
A directory traversal within the ‘ftpservlet’ of the FileCatalyst Workflow Web Portal allows files to be uploaded outside of the …