CVE-2023-30145
CRITICAL9.8EPSS 53.3%Server-Side Template Injection in Camaleon CMS
發布日:2023/5/26修改日:2024/2/16
描述
Camaleon CMS prior to 2.7.4 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the `formats` parameter.
受影響套件(1)
- RubyGems/camaleon_cmsfrom 0, < 2.7.4
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
參考連結(11)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2023-30145
- PATCHhttps://github.com/owen2345/camaleon-cms
- WEBhttp://packetstormsecurity.com/files/172593/Camaleon-CMS-2.7.0-Server-Side-Template-Injection.html
- WEBhttps://book.hacktricks.xyz/pentesting-web/ssti-server-side-template-injection
- WEBhttps://drive.google.com/file/d/11MsSYqUnDRFjcwbQKJeL9Q8nWpgVYf2r/view?usp=share_link
- WEBhttps://github.com/owen2345/camaleon-cms/commit/4485788c544eb1aae52ca613bd9626129e3df6ee
- WEBhttps://github.com/owen2345/camaleon-cms/issues/1052
- WEBhttps://github.com/owen2345/camaleon-cms/releases/tag/2.7.4
- WEBhttps://github.com/paragbagul111/CVE-2023-30145
- WEBhttps://github.com/rubysec/ruby-advisory-db/blob/master/gems/camaleon_cms/CVE-2023-30145.yml
- WEBhttps://portswigger.net/research/server-side-template-injection