CVE-2023-22621
Dashboard / Vulnerabilities / CVE-2023-22621
Summary:
Details: Strapi through 4.5.5 allows authenticated Server-Side Template Injection (SSTI) that can be exploited to execute arbitrary code on the server. A remote attacker with access to the Strapi admin panel can inject a crafted payload that executes code on the server into an email template that bypasses the validation checks that should prevent code execution.
References: https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/22xxx/CVE-2023-22621.json, https://nvd.nist.gov/vuln/detail/CVE-2023-22621, https://github.com/strapi/strapi/releases, https://strapi.io/blog/security-disclosure-of-vulnerabilities-cve, https://www.ghostccamm.com/blog/multi_strapi_vulns/
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
