CraftCMS version 3.7.59 is vulnerable to Server-Side Template Injection (SSTI). An authenticated attacker can inject Twig Template to User Photo Location field when setting User Photo Location in User Settings, lead to Remote Code Execution. NOTE: the vendor disputes this because only Administrators can add this Twig code, and (by design) Administrators are allowed to do that by default.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-3x74-v64j-qc3f | Withdrawn Advisory: CraftCMS Server-Side Template Injection vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 03 Jan 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-01-03T20:04:29.866Z
Reserved: 2023-04-07T00:00:00.000Z
Link: CVE-2023-30179
Updated: 2024-08-02T14:21:44.660Z
Status : Modified
Published: 2023-06-13T17:15:14.600
Modified: 2025-01-03T20:15:25.737
Link: CVE-2023-30179
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA