Aller au contenu

Fiche vulnérabilité

CVE-2023-22621 : faille élevée strapi strapi (CVSS 7.2)

Description

Strapi through 4.5.5 allows authenticated Server-Side Template Injection (SSTI) that can be exploited to execute arbitrary code on the server. A remote attacker with access to the Strapi admin panel can inject a crafted payload that executes code on the server into an email template that bypasses the validation checks that should prevent code execution.

En bref

Sévérité
Élevée (CVSS 7.2)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
19 avr. 2023
Dernière mise à jour
17 juin 2026

Produits concernés

  • strapi strapi

Références

Rechercher une autre vulnérabilité dans la base CVE