CVE Radar

CVE Radar Logo
CVERadar

Edition used by more than 30,000 companies in more than 150 countries.
Sign Up For Free

CVE-2024-37843

Medium Severity|Craftcms
30
SVRS
9.8
CVSSv3
0.89433
EPSS
TAGS
In The WildExploit Avaliable
VECTOR STRING
CVSS:3.1AV:NAC:LPR:NUI:NS:UC:HI:HA:H
PUBLICATION DATE2024-06-25
LAST MODIFIED2024-08-02

Deep CVE Analysis in Progress

The system is currently conducting an in-depth analysis of the selected CVE. This includes advanced correlation, vulnerability classification, and cross-referencing with real-time threat intelligence sources. Once the analysis is complete, the page will automatically update with enriched vulnerability data and actionable insights.

Security Intelligence Brief

1. What is this vulnerability and why does it matter?
CVE-2024-37843 is a critical SQL injection vulnerability affecting Craft CMS versions up to and including v3.7.31. This flaw exists within the GraphQL API endpoint. It matters significantly because it allows unauthenticated remote attackers to execute arbitrary SQL queries against the underlying database. Successful exploitation can lead to a complete compromise of data confidentiality, integrity, and availability, including sensitive data exfiltration and potential remote code execution in some configurations. The existence of published active exploits further elevates its importance, making it an immediate and severe threat to affected systems.
2. What are the CVSS score, severity level, and disclosure details?
The CVSS (Common Vulnerability Scoring System) Base Score for CVE-2024-37843 is 9.8. This score assigns a severity level of CRITICAL to the vulnerability. The vulnerability was first published by the National Vulnerability Database (NVD) and the GitHub Advisory Database on June 25, 2024. The NVD record was last modified on August 2, 2024, and the GitHub Advisory Database record was reviewed on July 19, 2024.
3. Which products, vendors, systems, and versions are affected?
  • Product: Craft CMS
  • Vendor: Pixel & Tonic (developer of Craft CMS)
  • Affected Versions: All versions of Craft CMS up to and including v3.7.31 are vulnerable.
4. What is the technical root cause and attack vector?
The technical root cause of CVE-2024-37843 is an Improper Neutralization of Special Elements used in an SQL Command, commonly known as SQL Injection (CWE-89). Specifically, the vulnerability arises in the GraphQL query processing logic where user-controlled parameters, such as 'orderBy', are directly incorporated into SQL queries without adequate sanitization or validation. The attack vector is network-based, targeting the GraphQL API endpoint of the Craft CMS application.
5. How can this vulnerability be exploited?
This vulnerability can be exploited by an unauthenticated attacker who crafts and sends malicious GraphQL queries containing SQL injection payloads to the vulnerable Craft CMS GraphQL API endpoint. The lack of proper input validation allows the injected SQL commands to be processed and executed by the backend database. Since no authentication or user interaction is required, any Craft CMS installation with GraphQL enabled and accessible over the network is susceptible to exploitation. Successful exploitation can lead to unauthorized database access, data manipulation, and potentially broader system compromise.
6. What mitigation steps and patches are available?
The primary mitigation step is to update Craft CMS to a version later than v3.7.31. This ensures that the patch addressing the SQL injection vulnerability is applied. In addition to patching, general mitigation strategies include:
  • Implementing Web Application Firewalls (WAFs) to detect and block malicious SQL injection attempts.
  • Ensuring robust input validation is in place for all user-supplied data, especially within API endpoints.
  • Following the principle of least privilege for database accounts and application permissions.
7. How can vulnerable systems be detected?
Vulnerable systems can be detected by identifying the version of Craft CMS running on the server. Any installation of Craft CMS at version v3.7.31 or older is considered vulnerable. Automated security scanning tools, particularly those capable of identifying SQL injection vulnerabilities in GraphQL API endpoints, can also be employed to detect susceptible systems. Regular software inventory and version checks are crucial for identifying outdated installations.
8. What are the indicators of compromise (IOCs)?
Indicators of Compromise (IOCs) for this vulnerability may include:
  • Unusual or unexpected SQL queries observed in database logs.
  • Unauthorized data modifications or deletions within the Craft CMS database.
  • Evidence of sensitive data exfiltration from the database.
  • Suspicious or anomalous network traffic directed at the GraphQL API endpoint.
  • Presence of known SQL injection payloads or error messages indicating SQL errors in web server or application logs.
  • Unauthorized user accounts or changes to existing user privileges within the Craft CMS application.
9. Which threat actors are known to exploit this vulnerability?
While the provided information states that "Active exploits have been published to exploit the vulnerability," specific threat actors or groups known to be exploiting CVE-2024-37843 are not named in the available data.
10. What public intelligence references and advisories exist?
Public intelligence references and advisories for CVE-2024-37843 include:
  • CVE Record: CVE-2024-37843, available on the National Vulnerability Database (NVD) and GitHub Advisory Database.
  • CWE: CWE-89, identifying the vulnerability as an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection').
  • Security Advisories and Blogs:
    • Miggo Security blog post detailing Craft CMS GraphQL API SQLi.
    • Information from the Vulnerability & Exploit Database.
    • Advisories from security vendors like SentinelOne.
11. What is the risk assessment and urgency level?
The risk assessment for CVE-2024-37843 is CRITICAL due to its CVSS Base Score of 9.8. This unauthenticated SQL injection vulnerability via the GraphQL API allows remote attackers to fully compromise the database, leading to high impacts on confidentiality, integrity, and availability. Given the critical severity and the confirmed existence of active exploits, the urgency level for addressing this vulnerability is IMMEDIATE. Organizations running affected versions of Craft CMS must apply the necessary patches without delay to prevent potential compromise.

No IOCs found for this CVE

TitleSoftware LinkDate
gsmith257-cyber/CVE-2024-37843-POChttps://github.com/gsmith257-cyber/CVE-2024-37843-POC2024-06-18
SOCRadar Logo

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence

Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.

CREATE FREE ACCOUNT
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs

No news found for this CVE

No tweets found for this CVE

Configuration 1
TypeVendorProduct
AppCraftcmscraft_cms
ReferenceLink
[email protected]https://blog.smithsecurity.biz/craft-cms-unauthenticated-sqli-via-graphql
GITHUBhttps://blog.smithsecurity.biz/craft-cms-unauthenticated-sqli-via-graphql
CWE IDCWE NameDescription
CWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')The software constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.