Description
PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template injection (SSTI) flaw. This vulnerability allows a malicious attacker to send customized commands to the server and execute arbitrary code on the affected system.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-w7vm-4v3j-vgpw | PyroCMS remote code execution vulnerability |
References
History
Thu, 17 Oct 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-10-17T15:41:17.594Z
Reserved: 2023-04-07T00:00:00.000Z
Link: CVE-2023-29689
Updated: 2024-08-02T14:14:39.855Z
Status : Modified
Published: 2023-08-04T15:15:10.137
Modified: 2024-11-21T07:57:23.383
Link: CVE-2023-29689
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA