First published: Fri Aug 04 2023(Updated: )
PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template injection (SSTI) flaw. This vulnerability allows a malicious attacker to send customized commands to the server and execute arbitrary code on the affected system.
Credit: Daniel Barros cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Pyrocms Pyrocms | =3.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-29689 is a remote code execution (RCE) vulnerability in PyroCMS 3.9.
CVE-2023-29689 can be exploited through a server-side template injection (SSTI) flaw, allowing an attacker to execute arbitrary code on the affected system.
CVE-2023-29689 has a severity score of 9.8, which is considered critical.
PyroCMS version 3.9 is affected by CVE-2023-29689.
To fix CVE-2023-29689, it is recommended to update PyroCMS to a version that contains a patch for the vulnerability.