Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Langsmith Bug can expose the Openai keys and users’ data through malicious agents

June 17, 2025

How to protect backups

June 17, 2025

Silver Fox Apt has on target Taiwan with sophisticated GH0Stcringe and Holdinghands Rats Malicious Programs

June 17, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Cisa Flags CRAFT CMS vulnerability cve-2025-23209 against the background of active attacks
Global Security

Cisa Flags CRAFT CMS vulnerability cve-2025-23209 against the background of active attacks

AdminBy AdminFebruary 21, 2025No Comments1 Min Read
Craft CMS Vulnerability
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


February 21, 2025Red LakshmananWeb -safety / vulnerability

CRIME CONDERATION CMS

Was a high -speed security disadvantage that affects the content management system (CMS) added US Agency for Cybersecurity and Infrastructure (CISA) to known exploited vulnerabilities (Ship) A catalog based on evidence of active operation.

Vulnerability in question Cve-2025-23209 (CVSS Assessment: 8.1), which affects the Sraft CMS version 4 and 5. It was addressed to the project services at the end of December 2024 in versions 4.13.8 and 5.5.8.

“Craft CMS contains a vulnerability of the code that allows you to execute the removed code because the vulnerable versions violate the security keys,” the agency said.

Cybersecurity

Vulnerability affects the next version of the software –

  • > = 5.0-RC1, <5.5.5
  • > = 4.0.0-RC1, <4.13.8

In the advice liberated The GitHub Craft CMS noted that all unprotected craft versions affect security defect.

“If you cannot upgrade the secured version, then the safety key and its privacy key will help mitigate the problem,” the message said.

Currently, it is unclear how the user’s security keys were violated and in what context. In order to facilitate the risk of vulnerability, it is recommended that the Federal Civil Executive Agency (FCEB) apply the necessary fixes by March 13, 2025.

Found this article interesting? Keep track of us further Youter  and LinkedIn To read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Langsmith Bug can expose the Openai keys and users’ data through malicious agents

June 17, 2025

How to protect backups

June 17, 2025

Silver Fox Apt has on target Taiwan with sophisticated GH0Stcringe and Holdinghands Rats Malicious Programs

June 17, 2025

Google warns about scattered spider attacks focused on IT -commander by US insurance firms

June 17, 2025

Password “B” in Sitecore XP Sparks Sparks Erriss RCE when deploying businesses

June 17, 2025

Are you forgotten accounts of advertising services that leave you risk?

June 17, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Langsmith Bug can expose the Openai keys and users’ data through malicious agents

June 17, 2025

How to protect backups

June 17, 2025

Silver Fox Apt has on target Taiwan with sophisticated GH0Stcringe and Holdinghands Rats Malicious Programs

June 17, 2025

Google warns about scattered spider attacks focused on IT -commander by US insurance firms

June 17, 2025

Password “B” in Sitecore XP Sparks Sparks Erriss RCE when deploying businesses

June 17, 2025

Are you forgotten accounts of advertising services that leave you risk?

June 17, 2025

New Flodrix Botnet Option Operates Langflow Ai Server RCE BUG to launch DDOS ATTACKS

June 17, 2025

Lack of the TP-Link Cve-2023-33538 router under active operation, CISA releases an immediate warning

June 17, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Langsmith Bug can expose the Openai keys and users’ data through malicious agents

June 17, 2025

How to protect backups

June 17, 2025

Silver Fox Apt has on target Taiwan with sophisticated GH0Stcringe and Holdinghands Rats Malicious Programs

June 17, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.