June 13, 2023, 5:15 p.m. |

National Vulnerability Database web.nvd.nist.gov

CraftCMS version 3.7.59 is vulnerable to Server-Side Template Injection (SSTI). An authenticated attacker can inject Twig Template to User Photo Location field when setting User Photo Location in User Settings, lead to Remote Code Execution.

code code execution cve inject injection location photo remote code remote code execution server settings ssti template template injection version vulnerable

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

Senior Manager - Vendor management/ Compliance

@ Sprinklr | India - Haryana - Gurgaon

DevSecOps Engineer

@ Swiss Re | Hyderabad, TG, IN

Cyber Security Architect

@ Endeavour Group | Surry Hills, Australia

Principal Product Manager (Network/Security Management) - NetSec

@ Palo Alto Networks | Bengaluru, India

Lead Security Analyst

@ Deloitte | Sydney, NSW, AU