Looking for the vulnerability index of Invicti's legacy products?
Craft CMS Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-30179) - Vulnerability Database

Craft CMS Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-30179)

Description

CraftCMS version 3.7.59 is vulnerable to Server-Side Template Injection (SSTI). An authenticated attacker can inject Twig Template to User Photo Location field when setting User Photo Location in User Settings, lead to Remote Code Execution.

References

Related Vulnerabilities