First published: Tue Jun 13 2023(Updated: )
** DISPUTED ** CraftCMS version 3.7.59 is vulnerable to Server-Side Template Injection (SSTI). An authenticated attacker can inject Twig Template to User Photo Location field when setting User Photo Location in User Settings, lead to Remote Code Execution. NOTE: the vendor disputes this because only Administrators can add this Twig code, and (by design) Administrators are allowed to do that by default.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Craftcms Craft Cms | =3.7.59 | |
composer/craftcms/cms | <4.4.2 | 4.4.2 |
=3.7.59 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-30179 is a vulnerability in CraftCMS version 3.7.59 that allows an authenticated attacker to inject Twig templates and potentially execute remote code.
CVE-2023-30179 has a severity rating of 7.2 out of 10, which is classified as high.
CVE-2023-30179 allows an attacker to inject Twig templates into the User Photo Location field, potentially leading to remote code execution.
To fix CVE-2023-30179, you should update CraftCMS to a version that is not affected by the vulnerability.
More information about CVE-2023-30179 can be found in the provided references.