CVE-2024-56145 | Craft CMS up to 4.13.1/5.5.1 Configuration php.ini register_argc_argv code injection (GHSA-2p6p-9rc9-62j9)
A vulnerability was found in Craft CMS up to 4.13.1/5.5.1. It has been classified as critical. Affected is an unknown function of the file php.ini of the component Configuration Handler. The manipulation of the argument register_argc_argv leads to code injection.
This vulnerability is traded as CVE-2024-56145. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.