Vulnerability record

CVE-2023-22621

Severity: HighExploitation: No known exploitation

Patch status

No official fix confirmed yet

Until a fix ships, follow the vendor's mitigations, limit exposure of affected systems, and watch this record for a patch.

Description

Strapi through 4.5.5 allows authenticated Server-Side Template Injection (SSTI) that can be exploited to execute arbitrary code on the server. A remote attacker with access to the Strapi admin panel can inject a crafted payload that executes code on the server into an email template that bypasses the validation checks that should prevent code execution.

Source: NIST National Vulnerability Database. Official vulnerability data, reproduced as published.

Affected products

Products affected by this vulnerability, with versions and the source of each entry
ProductVendorAffected versionsFixed inSource
StrapiStrapi>= 3.0.0, < 4.5.64.5.6NVD

Sources: NVD = NIST National Vulnerability Database.

Intelligence timeline

Developments from the last 30 days, newest first.

  1. CVSS scoredUpdate

    CVE-2023-22621 scored CVSS 7.2

    Basis: NIST National Vulnerability Database

Coverage

References

  • github.com https://github.com/strapi/strapi/releases
  • strapi.io https://strapi.io/blog/security-disclosure-of-vulnerabilities-cve
  • ghostccamm.com https://www.ghostccamm.com/blog/multi_strapi_vulns/