
Cloud Vulnerability DB
A community-led vulnerabilities database
CraftCMS version 3.7.59 was reported to have a Server-Side Template Injection (SSTI) vulnerability identified as CVE-2023-30179. The vulnerability was reported to allow an authenticated attacker to inject Twig Template into the User Photo Location field when setting User Photo Location in User Settings, potentially leading to Remote Code Execution. However, this vulnerability is disputed by the vendor (GitHub Discussion).
The reported vulnerability involves the ability to inject Twig templates into the User Photo Location field in User Settings. The injection point was identified in the admin page under User Settings -> Settings, where Twig template code could be injected into the User Photo Location parameter. A proof of concept showed that by uploading a new avatar after injection, the SSTI payload could be triggered (Exploit Details). The vulnerability has been assigned a CVSS v3.1 base score of 7.2 HIGH with vector string CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H (NVD).
If exploited, the vulnerability could potentially lead to Remote Code Execution on the affected system. However, the vendor disputes the severity of this impact since only administrators can add Twig code, which is an intended functionality (GitHub Discussion).
The vulnerability requires authentication and administrative access to exploit. The vendor states that this is by design, as administrators are intentionally allowed to execute Twig code for dynamic settings based on specific business needs. Additionally, the vendor recommends setting allowAdminChanges to false in production, which prevents any settings modifications and significantly reduces the attack surface (GitHub Discussion).
The vendor recommends following their security best practices, specifically setting allowAdminChanges to false in production environments. This setting effectively removes the ability to change any Settings, thus mitigating the potential risk even if an administrator account is compromised (GitHub Discussion).
The vulnerability has been disputed by the CraftCMS team, who maintain that the reported behavior is an intended functionality for administrators. GitHub Security Lab has acknowledged the dispute and updated their advisory database accordingly (GitHub Discussion).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."