CraftCMS version 3.7.59 is vulnerable to Server-Side Template Injection (SSTI)....
Vulnerability Description
CraftCMS version 3.7.59 is vulnerable to Server-Side Template Injection (SSTI). An authenticated attacker can inject Twig Template to User Photo Location field when setting User Photo Location in User Settings, lead to Remote Code Execution. NOTE: the vendor disputes this because only Administrators can add this Twig code, and (by design) Administrators are allowed to do that by default.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-30179
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/craftcms/cms/blob/develop/CHANGELOG.md#442---2023-03-14
- https://datnlq.gitbook.io/cve/craft-cms/cve-2023-30179-server-side-template-injection
- https://github.com/github/advisory-database/pull/2443#issuecomment-1610634200
- https://github.com/github/advisory-database/pull/2443#issuecomment-1610040714
More from n/a
View All →Affected Vendor
Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.