Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
PoC_CVE-2025-32432 — CraftCMS CVE-2025-32432 - Clean PoC | Kitploit
Tools/GitHubGitHub/n40y/poc_cve-2025-32432
Vulnerability AnalysisCode AnalysisExploitationWeb Application ExploitationPenetration TestingLearning & Education
GitHubn40y/poc_cve-2025-32432

PoC_CVE-2025-32432

CraftCMS CVE-2025-32432 - Clean PoC

View Repository
73 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CraftCMS CVE-2025-32432 - Clean PoC

Cleaned-up and improved version of the original Proof of Concept.

Python License

Credits

  • Original research: Orange Cyberdefense & Chirag Artani
  • Cleaned-up and improved version: n40y

License

This project is licensed under MIT.
See the LICENSE file for more details.

Disclaimer

This PoC is provided solely for educational purposes and authorized testing (CTF, security audits with explicit written permission).

Any use on systems without authorization is illegal. The author declines all responsibility in case of misuse.

Vulnerable versions

  • Craft CMS 3.x : < 3.9.15
  • Craft CMS 4.x : < 4.14.15
  • Craft CMS 5.x : < 5.6.17

Improvements

  • Complete removal of Chinese comments
  • Automatic Craft CMS version detection
  • Restructured, more maintainable code
  • Better error and timeout handling
  • Clear messages in French/English

Project structure

craftcms-cve-2025-32432-poc/
├── craftcms_rce_php_check.py
├── craftcms_final_payload.py
├── requirements.txt
├── README.md
├── LICENSE
└── .gitignore

Installation

git clone https://github.com/n40y/craftcms-cve-2025-32432-poc.git
cd craftcms-cve-2025-32432-poc

pip3 install -r requirements.txt

Usage:

1. Quick check

python3 craftcms_rce_php_check.py -u https://target.com

# Ou avec une liste
python3 craftcms_rce_php_check.py -f urls.txt -t 10

2. Full exploitation (RCE)

python3 craftcms_final_payload.py -u https://victim.com -c "id"

Options

-u, --url → URL cible (obligatoire)
-c, --cmd → Commande système à exécuter (obligatoire)
-a, --asset → AssetId valide connu (optionnel)
-s, --scan-max → Max assetId à scanner (défaut: 300)
Download Tool