CVE-2023-30179

HIGH

CraftCMS < 4.4.2 - Authenticated Server-Side Template Injection via User Photo Location Field

Title source: llm
STIX 2.1

Description

CraftCMS version 3.7.59 is vulnerable to Server-Side Template Injection (SSTI). An authenticated attacker can inject Twig Template to User Photo Location field when setting User Photo Location in User Settings, lead to Remote Code Execution. NOTE: the vendor disputes this because only Administrators can add this Twig code, and (by design) Administrators are allowed to do that by default.

Scores

CVSS v3 7.2
EPSS 0.0220
EPSS Percentile 80.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-94
Status published
Products (2)
craftcms/cms 0 - 4.4.2Packagist
craftcms/craft_cms 3.7.59
Published Jun 13, 2023
Tracked Since Feb 18, 2026