PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template injection (SSTI) flaw. This vulnerability allows a malicious attacker to send customized commands to the server and execute arbitrary code on the affected system.
References
Configurations
History
21 Nov 2024, 07:57
Type | Values Removed | Values Added |
---|---|---|
References | () http://packetstormsecurity.com/files/174088/Pyro-CMS-3.9-Server-Side-Template-Injection.html - | |
References | () https://cupc4k3.lol/ssti-leads-to-rce-on-pyrocms-7515be27c811 - Exploit, Third Party Advisory | |
Summary |
|
Information
Published : 2023-08-04 15:15
Updated : 2024-11-21 07:57
NVD link : CVE-2023-29689
Mitre link : CVE-2023-29689
CVE.ORG link : CVE-2023-29689
JSON object : View
Products Affected
pyrocms
- pyrocms
CWE