Sploitus

CVE-2025-6384

1 known exploit for CVE-2025-6384

Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of CrafterCMS allows authenticated developers to execute OS commands via Groovy Sandbox Bypass. By inserting malicious Groovy elements, an attacker may bypass Sandbox restrictions and obtain RCE (Remote Code Execution). This issue affects CrafterCMS: from 4.0.0 through 4.2.2.

Affected products
Crafter Cms, Groovy
Craftercms
< 4.3.0
CVSS 3.1
9.1 CRITICAL
EPSS
0.9% (55th percentile)
Weakness
CWE-913
NVD status
Analyzed
Published
2025-06-19
Attack patterns
CAPEC-253
CVE-2025-6384 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2025-6384

Proof-of-concept code and exploit modules indexed by Sploitus