Files or Directories Accessible to External Parties in Craft CMS - CVE-2024-52292

 

Files or Directories Accessible to External Parties in Craft CMS - CVE-2024-52292

Published: November 13, 2024 / Updated: June 16, 2026


Vulnerability identifier: #VU134650
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-52292
CWE-ID: CWE-552
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to files or directories accessible to external parties in the mail notification template functionality when rendering a crafted system notification template that calls the dataUrl function with an absolute file path. A remote user can modify a system notification template and trigger a corresponding system email to disclose sensitive information.

Exploitation requires write access to system notification templates and the ability to trigger the related notification email.


Affected software

Craft CMS

How to mitigate CVE-2024-52292

Install security update from vendor's website.

Craft CMS - addressed in versions 4.12.8, 5.4.9

External References

Related Security Bulletins