Executive summary
Public evidence documents CVE-2024-58136. This report does not assess any organization.
Technical analysis
Craft CMS contains an external control of assumed-immutable web parameter vulnerability. This vulnerability could allow an unauthenticated client to introduce arbitrary values, such as PHP code, to a known local file location on the server. This vulnerability could be chained with CVE-2024-58136 as represented by CVE-2025-32432.
Evidence and sources
Public evidence for CVE-2024-58136 with preserved provenance.
CVE-2024-58136 Craft CMS External Control of Assumed-Immutable Web Parameter Vulnerability Craft CMS contains an external control of assumed-immutable web parameter vulnerability. This vulnerability could allow an unauthenticated client to introduce arbitrary values, such as PHP code, to a known local file location on the server. This vulnerability could be chained with CVE-2024-58136 as represented by CVE-2025-32432.
IOCs
No public IOC is available.
CVEs and affected products
Craft CMS External Control of Assumed-Immutable Web Parameter Vulnerability
ATT&CK mapping
No ATT&CK mapping is available.
Detection content
Sigma rules, YARA rules, Splunk SPL, and KQL detection logic.
Threat hunting
Hypothesis-driven hunt procedures and telemetry checklist.
Remediation
Containment actions, patching notes, and credential steps.
Historical relationships
No published historical relationship is available.
Timeline and change history
Confidence and caveats
1.0
⚠️ Public CTI only; no organizational exposure is asserted.
⚠️ CVSS and EPSS metadata were not present in the retrieved evidence payload.