Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-w7vm-4v3j-vgpw: PyroCMS remote code execution vulnerability

PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template injection (SSTI) flaw. This vulnerability allows a malicious attacker to send customized commands to the server and execute arbitrary code on the affected system.

ghsa
#vulnerability#git#rce

PyroCMS remote code execution vulnerability

Moderate severity GitHub Reviewed Published Aug 4, 2023 to the GitHub Advisory Database • Updated Aug 4, 2023

Related news

Pyro CMS 3.9 Server-Side Template Injection

Pyro CMS version 3.9 suffers from a server-side template injection vulnerability.

CVE-2023-29689

PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template injection (SSTI) flaw. This vulnerability allows a malicious attacker to send customized commands to the server and execute arbitrary code on the affected system.