CVE-2023-22621
Strapi through 4.5.5 allows authenticated Server-Side Template Injection (SSTI) that can be exploited to execute arbitrary code on the server.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 76.8%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
Strapi through 4.5.5 allows authenticated Server-Side Template Injection (SSTI) that can be exploited to execute arbitrary code on the server. A remote attacker with access to the Strapi admin panel can inject a crafted payload that executes code on the server into an email template that bypasses the validation checks that should prevent code execution.
- CVSS 3.1
- 7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 76.83% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-74
- Affected
- strapi/strapi
- Source
- cve@mitre.org
References
- https://github.com/strapi/strapi/releasesRelease Notes
- https://strapi.io/blog/security-disclosure-of-vulnerabilities-cveVendor Advisory
- https://www.ghostccamm.com/blog/multi_strapi_vulns/Exploit, Third Party Advisory
- https://github.com/strapi/strapi/releasesRelease Notes
- https://strapi.io/blog/security-disclosure-of-vulnerabilities-cveVendor Advisory
- https://www.ghostccamm.com/blog/multi_strapi_vulns/Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.