Craft CMS Improper Control of Generation of Code (Code Injection) Vulnerability - CVE-2023-30179 - Vulnerability Database

Craft CMS Improper Control of Generation of Code (Code Injection) Vulnerability - CVE-2023-30179

High
Reference: CVE-2023-30179
Title: Craft CMS Improper Control of Generation of Code (Code Injection) Vulnerability
Overview:

CraftCMS version 3.7.59 is vulnerable to Server-Side Template Injection (SSTI). An authenticated attacker can inject Twig Template to User Photo Location field when setting User Photo Location in User Settings lead to Remote Code Execution.