CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2025-0502: Transmission of Private Resources into a New Sphere in Crafter Engine

6.9 CVSS

Description

Transmission of Private Resources into a New Sphere ('Resource Leak') vulnerability in CrafterCMS Engine on Linux, MacOS, x86, Windows, 64 bit, ARM allows Directory Indexing, Resource Leak Exposure.This issue affects CrafterCMS: from 4.0.0 before 4.0.8, from 4.1.0 before 4.1.6.

Classification

CVE ID: CVE-2025-0502

CVSS Base Severity: MEDIUM

CVSS Base Score: 6.9

Affected Products

Vendor: CrafterCMS

Product: CrafterCMS

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 11.5% (scored less or equal to compared to others)

EPSS Date: 2025-02-13 (when was this score calculated)

References

https://craftercms.com/docs/current/security/advisory.html#cv-2025011501

Timeline