CVE-2025-32432 IBM QRadar · QRadar

Detect CVE-2025-32432: Craft CMS Remote Code Injection in IBM QRadar

Detects exploitation of CVE-2025-32432, a critical code injection vulnerability (CWE-94) in Craft CMS that allows remote attackers to execute arbitrary code. This vulnerability is actively exploited in the wild (CISA KEV) and targets Craft CMS installations via malicious template or input injection vectors.

MITRE ATT&CK

Tactic
Initial Access Execution Persistence

QRadar Detection Query

IBM QRadar (QRadar)
sql
SELECT
  DATEFORMAT(starttime, 'YYYY-MM-dd HH:mm:ss') AS event_time,
  sourceip,
  destinationip,
  URL,
  username,
  "HTTP Method",
  "HTTP Response Code",
  QIDNAME(qid) AS event_name,
  logsourcename(logsourceid) AS log_source
FROM events
WHERE
  LOGSOURCETYPENAME(logsourceid) IN ('IBM Security Network IPS (GV2)', 'Apache HTTP Server', 'Microsoft IIS', 'NGINX')
  AND (URL ILIKE '%/actions/%' OR URL ILIKE '%/admin/%' OR URL ILIKE '%/index.php%')
  AND "HTTP Method" = 'POST'
  AND (
    URL ILIKE '%phpinfo%'
    OR URL ILIKE '%base64_decode%'
    OR URL ILIKE '%eval(%'
    OR URL ILIKE '%system(%'
    OR URL ILIKE '%exec(%'
    OR URL ILIKE '%assert(%'
    OR URL ILIKE '%shell_exec(%'
    OR "HTTP Post Data" ILIKE '%phpinfo%'
    OR "HTTP Post Data" ILIKE '%eval(%'
    OR "HTTP Post Data" ILIKE '%base64_decode%'
  )
  AND starttime > NOW() - 86400000
ORDER BY starttime DESC
LIMIT 500
critical severity medium confidence

QRadar AQL query detecting POST requests to Craft CMS endpoints with code injection patterns associated with CVE-2025-32432 across IPS, IIS, Apache, and NGINX log sources.

Data Sources

IBM Security Network IPSMicrosoft IISApache HTTP ServerNGINX

Required Tables

events

False Positives & Tuning

  • Vulnerability scanning tools producing benign probe traffic that matches PHP injection signatures
  • Craft CMS administrative operations that use encoded content in POST bodies
  • Threat intelligence feed ingestion pipelines that process and forward raw exploit samples through log pipelines

Other platforms for CVE-2025-32432


Testing Methodology

Validate this detection against 4 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.

  1. Test 1CVE-2025-32432 PHP Info Probe via Craft CMS Action Endpoint

    Expected signal: HTTP POST to /actions/test with 'phpinfo()' in request body; web server access log entry; potential 200 response with PHP environment disclosure

  2. Test 2CVE-2025-32432 Base64-Encoded Command Injection

    Expected signal: HTTP POST to /actions/users/login with 'base64_decode' in POST body; web server log capturing encoded payload; potential process spawn of 'id' command from php parent

  3. Test 3CVE-2025-32432 Webshell Drop via File Write Injection

    Expected signal: POST to /actions/ with file_put_contents payload; new file 'shell.php' created in web root with anomalous timestamp; subsequent GET to /shell.php with cmd parameter; process execution of 'id' spawned from PHP

  4. Test 4CVE-2025-32432 Reverse Shell Payload Simulation

    Expected signal: HTTP POST to Craft CMS action endpoint with bash reverse shell command in body; outbound TCP connection from web server to attacker IP on port 4444; process tree showing bash spawned from php parent; network flow anomaly for web server initiating outbound connection

Unlock Pro Content

Get the full detection package for CVE-2025-32432 including response playbook, investigation guide, and atomic red team tests.

Response PlaybookInvestigation GuideHunting QueriesAtomic Red Team TestsTuning Guidance

Related Detections