Skip to content

Commit f24801a

Browse files
committed
Update doc
1 parent 9d0d120 commit f24801a

File tree

1 file changed

+4
-0
lines changed

1 file changed

+4
-0
lines changed

documentation/modules/exploit/linux/http/craftcms_preauth_rce_cve_2025_32432.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -81,6 +81,10 @@ The module has the following option:
8181
For example, if you are targeting a Craft CMS version from the `>= 3.0.0`, `< 3.9.14`, make sure to specify the correct `ASSET_ID`.
8282
This is necessary for successful exploitation when dealing with these versions.
8383

84+
Craft CMS uses the notion of an "Asset" to manage files and media such as images and documents; each asset has a unique ID.
85+
This module does not perform bruteforcing of asset IDs to avoid noisy and inefficient exploitation attempts.
86+
87+
8488
## Scenarios
8589

8690
#### Successful Exploitation Against Craft CMS 5.5.0

0 commit comments

Comments
 (0)