PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template injection (SSTI) flaw. This vulnerability allows a malicious attacker to send customized commands to the server and execute arbitrary code on the affected system.
References
Configurations
History
21 Nov 2024, 07:57
Type | Values Removed | Values Added |
---|---|---|
References | () http://packetstormsecurity.com/files/174088/Pyro-CMS-3.9-Server-Side-Template-Injection.html - | |
References | () https://cupc4k3.lol/ssti-leads-to-rce-on-pyrocms-7515be27c811 - Exploit, Third Party Advisory |
09 Aug 2023, 18:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
09 Aug 2023, 17:37
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://cupc4k3.lol/ssti-leads-to-rce-on-pyrocms-7515be27c811 - Exploit, Third Party Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
CWE | NVD-CWE-Other | |
First Time |
Pyrocms pyrocms
Pyrocms |
|
CPE | cpe:2.3:a:pyrocms:pyrocms:3.9:*:*:*:*:*:*:* |
04 Aug 2023, 15:27
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-08-04 15:15
Updated : 2024-11-21 07:57
NVD link : CVE-2023-29689
Mitre link : CVE-2023-29689
CVE.ORG link : CVE-2023-29689
JSON object : View
Products Affected
pyrocms
- pyrocms
CWE