Critical Zero-Day Attack on Craft CMS: How Hackers Exploited Dual Vulnerabilities to Breach Servers

Listen to this Post

Featured Image
Craft CMS, a popular content management system trusted by many developers and businesses for its flexibility and customization, has been hit by a coordinated zero-day cyberattack involving two newly discovered vulnerabilities. This attack chain allowed threat actors to gain full control of servers, install backdoors, and exfiltrate sensitive data — all while exploiting previously unknown flaws.

Discovered and reported by Orange Cyberdefense’s Computer Security Incident Response Team (CSIRT), the breach highlighted the danger of chaining vulnerabilities across software platforms — in this case, Craft CMS and the Yii PHP framework it uses.

Cybersecurity experts have confirmed that both vulnerabilities were actively exploited in the wild before patches were released. The attackers used a sophisticated two-stage technique that allowed for remote code execution, file uploads, and further compromise of affected systems.

Below, we’ll break down the key findings, how the attack unfolded, what was done to fix it, and the security implications going forward.

the Cyberattack in

  • Two zero-day vulnerabilities were exploited in a chained attack targeting Craft CMS.
  • The flaws enabled remote code execution and arbitrary file upload on vulnerable servers.
  • The attack was first uncovered by Orange Cyberdefense while investigating a compromised system.

– The vulnerabilities are:

  • CVE-2025-32432: Remote Code Execution (RCE) in Craft CMS.
  • CVE-2024-58136: Input validation flaw in the Yii framework.
  • Hackers began by exploiting CVE-2025-32432, injecting a malicious return URL in a specially crafted request.
  • This data was stored in a PHP session file and sent back as part of the HTTP response.
  • In the next phase, attackers exploited the Yii framework flaw to execute this PHP code on the server.
  • This allowed them to upload a PHP-based file manager, enabling deeper system access.
  • Further malicious activities were detected, including the installation of additional backdoors.
  • Exfiltration of server data was confirmed by Orange Cyberdefense analysts.
  • The security flaw in Yii (CVE-2024-58136) was patched in version 2.0.52 on April 9.
  • Craft CMS released fixes on April 10 for its platform in versions 3.9.15, 4.14.15, and 5.6.17.
  • Despite using an older Yii version (2.0.51), Craft CMS’s fix prevents the attack chain from being triggered.
  • The ethical hacking team, SensePost, provided detailed insights into the attack.
  • Craft CMS recommends refreshing your CRAFT_SECURITY_KEY if a breach is suspected.
  • Admins should also refresh all private keys, such as those used for S3 or Stripe integrations.
  • Rotating database credentials is strongly advised to prevent lingering access.
  • Admins can also enforce a password reset for all users as a precaution.
  • The report includes an appendix with indicators of compromise (IP addresses, file names).
  • This is not the first time Craft CMS has faced such issues — another RCE (CVE-2025-23209) was flagged in February.
  • The combination of platform vulnerability and third-party framework flaws created an ideal condition for a multi-stage attack.
  • Orange Cyberdefense warns that attackers are still exploiting systems with delayed patching.
  • Craft CMS has not yet upgraded Yii within the platform but claims the current patch is effective.
  • The flaw in Yii was crucial but couldn’t be triggered without the Craft CMS bug.
  • Attackers used chained exploits in a highly targeted and strategic manner.
  • The breach highlights the risks of dependency vulnerabilities in open-source platforms.
  • Incident response teams are urging rapid patching across the developer community.
  • Organizations using Craft CMS are advised to act immediately to secure their environments.
  • This event demonstrates how even lesser-known CMS platforms are not immune to advanced persistent threats.
  • Full technical details and exploit timelines are available via SensePost’s official publication.
  • Ongoing investigations may uncover further affected assets or methods of compromise.

What Undercode Say:

The recent compromise of Craft CMS underlines a critical truth in modern cybersecurity: layered security is only as strong as its weakest dependency. What makes this breach so alarming is not merely the fact that two zero-day vulnerabilities were exploited, but the sophistication with which they were combined. The attackers demonstrated a clear understanding of Craft CMS’s architecture and its relationship with the Yii PHP framework.

Chaining CVE-2025-32432 with CVE-2024-58136 wasn’t a lucky shot — it was the result of strategic reconnaissance and precision exploitation. The initial entry point via a manipulated “return URL” parameter might seem simple, but the subsequent execution of PHP code through JSON payload manipulation reveals deep technical planning.

The Yii framework vulnerability was the perfect follow-up, enabling the execution of a payload that had already been silently dropped into session files. This reflects a growing trend in exploit development: attackers are no longer relying on brute force or obvious malware. They are leveraging application logic and behavior — manipulating how trusted systems handle and store user input.

Craft CMS, while not as mainstream as WordPress, is widely used in enterprise projects due to its flexibility. That same modularity makes it more complex and potentially more vulnerable if integrations aren’t closely managed. The fact that Yii was not upgraded in the patch adds another layer of concern. While the attack chain is reportedly “neutralized,” keeping outdated libraries embedded in a platform may pose long-term risks.

This breach also echoes the importance of dependency visibility. How many developers using Craft CMS knew it relied on Yii? How many actually monitor sub-dependencies for zero-days? Very few. And that’s a major problem.

For enterprise developers and DevSecOps teams, this is a wake-up call to integrate Software Composition Analysis (SCA) tools into CI/CD pipelines. Knowing your stack isn’t just good practice — it’s a necessity in a world where supply chain attacks are increasing in frequency and impact.

Moreover, organizations should implement runtime application self-protection (RASP) and extended detection and response (XDR) strategies to detect suspicious behavior, even when an attacker uses novel zero-days.

The final lesson here is that patching

As threat actors evolve, defenders must do the same. Monitoring, threat intelligence, and proactive architecture reviews are essential. And for anyone still underestimating the security implications of CMS software — this incident should end the debate.

Fact Checker Results

  • Both CVEs (CVE-2025-32432 & CVE-2024-58136) are confirmed and actively exploited.
  • Craft CMS and Yii have released patches, but the Yii version within Craft remains outdated.
  • The reported attack chain and mitigation steps have been validated by Orange Cyberdefense and SensePost.

References:

Reported By: www.bleepingcomputer.com
Extra Source Hub:
https://www.stackexchange.com
Wikipedia
Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

Join Our Cyber World:

💬 Whatsapp | 💬 Telegram