Input validation error in Craft CMS - CVE-2025-35939

 

Input validation error in Craft CMS - CVE-2025-35939

Published: June 3, 2025


Vulnerability identifier: #VU110085
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-35939
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to write arbitrary contents to session files.

The vulnerability exists due to Craft CMS does not sanitize data before writing them into session files with predictable file names and location. A remote attacker can abuse this to write arbitrary PHP code into a known location of the system and later execute it using a different vulnerability.


Affected software

Craft CMS

How to mitigate CVE-2025-35939

Install updates from vendor's website.

Craft CMS - addressed in versions 4.15.3, 5.7.5

External References

Related Security Bulletins