Vulnerability record · CVE-2024-37843 · published 25 June 2024
CVE-2024-37843: Craft CMS SQL injection via GraphQL API endpoint
Craftcms · Craft Cms
Craft CMS up to v3.7.31 contains a SQL injection flaw reachable through its GraphQL API endpoint. The CVSS vector indicates the attack is network-reachable with no authentication or user interaction, and the impact spans confidentiality, integrity and availability. Because the endpoint is public-facing in typical deployments, this is a serious pre-auth injection risk.
Description
Craft CMS up to v3.7.31 was discovered to contain a SQL injection vulnerability via the GraphQL API endpoint.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication and no user interaction, combined with a very high EPSS percentile, makes this a top remediation priority.
What it is
Craft CMS up to v3.7.31 contains a SQL injection flaw reachable through its GraphQL API endpoint. The CVSS vector indicates the attack is network-reachable with no authentication or user interaction, and the impact spans confidentiality, integrity and availability. Because the endpoint is public-facing in typical deployments, this is a serious pre-auth injection risk.
Impact
An attacker can inject arbitrary SQL through the GraphQL API, potentially reading, modifying or deleting database contents and disrupting the application. With no privileges required, the exposure is broad.
Attack surface
Reached over the network via the GraphQL API endpoint; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are needed. The description does not specify which GraphQL query or field is vulnerable.
Exploitation
Not listed in CISA KEV and no ransomware usage documented. EPSS is 0.53242 (98.9th percentile), indicating a high modeled likelihood of exploitation, but the only references are tagged as broken links, so no confirmed public exploit is documented in this record.
What to do
- Upgrade Craft CMS to a version above 3.7.31 as soon as a fixed release is available; confirm the patched version from the vendor.
- If immediate upgrade is not possible, restrict or disable the GraphQL API endpoint and limit it to trusted networks or authenticated users.
- Apply input validation and parameterized queries for any custom GraphQL resolvers that touch the database.
- Monitor and rate-limit GraphQL requests, and block requests containing obvious SQL injection patterns.
- Review database accounts used by Craft CMS and apply least privilege to limit the impact of a successful injection.
Detection
- Inspect web and GraphQL access logs for anomalous query strings, SQL keywords, or unusual GraphQL operations targeting the API endpoint.
- Enable database query logging and look for unexpected or malformed SQL generated from the application.
- Alert on high volumes of GraphQL requests from single sources or requests returning database error messages.
- Correlate Craft CMS application logs with database errors to identify injection attempts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-37843 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-37843), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.