GHSA-j7fx-v37j-v3w7
Dashboard / Vulnerabilities / GHSA-j7fx-v37j-v3w7
Summary: Craft CMS Vulnerable to Server-Side Template Injection
Details: Craft CMS through 3.0.34 allows remote authenticated administrators to read sensitive information via server-side template injection, as demonstrated by a `{%` string for `craft.app.config.DB.user` and `craft.app.config.DB.password` in the URI Format of the Site Settings, which causes a cleartext username and password to be displayed in a URI field.
References: https://nvd.nist.gov/vuln/detail/CVE-2018-20465, https://github.com/phuctam/Server-Side-Template-Injection-in-CraftCMS-/issues/1, https://github.com/craftcms/cms, https://github.com/craftcms/cms/blob/master/CHANGELOG-v3.md
Affected packages
Package
Name: craftcms/cms
Purl: pkg:composer/craftcms/cms
Affected ranges
Type: ECOSYSTEM
Events:
