Description
Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, an authenticated administrator can achieve Remote Code Execution (RCE) by injecting a Server-Side Template Injection (SSTI) payload into Twig template fields (e.g., Email Templates). By calling the craft.app.fs.write() method, an attacker can write a malicious PHP script to a web-accessible directory and subsequently access it via the browser to execute arbitrary system commands. This vulnerability is fixed in 4.17.0-beta.1 and 5.9.0-beta.1.
Remediation
References
Related Vulnerabilities
WebLogic CVE-2017-10336 Vulnerability (CVE-2017-10336)
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2020-35480)
MongoDb Improper Handling of Exceptional Conditions Vulnerability (CVE-2020-7923)
Dolibarr Files or Directories Accessible to External Parties Vulnerability (CVE-2023-33568)
WordPress Plugin Accept Donations with PayPal Cross-Site Scripting (1.3.1)