HTB Orion: CraftCMS CVE-2025-32432 RCE Exploited in Hack The Box Challenge
A Hack The Box machine named Orion, rated Very Easy, runs CraftCMS 5.6.16 on nginx, which is vulnerable to an unauthenticated remote code execution flaw tracked as CVE-2025-32432. The vulnerability exploits Yii's object-configuration system via the image transform endpoint, allowing attackers to instantiate arbitrary PHP classes through attacker-controlled JSON. A security researcher manually bypassed CSRF protections by extracting session cookies and token values from the login page before confirming arbitrary function execution. The Metasploit module for the exploit initially failed due to a missing VHOST setting and a persistent reverse shell connectivity issue, despite the target sending SYN packets to the listener. The researcher ultimately pivoted to a webshell-based approach to achieve command execution without requiring an inbound connection.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in