{"id":"CVE-2023-30179","details":"CraftCMS version 3.7.59 is vulnerable to Server-Side Template Injection (SSTI). An authenticated attacker can inject Twig Template to User Photo Location field when setting User Photo Location in User Settings, lead to Remote Code Execution. NOTE: the vendor disputes this because only Administrators can add this Twig code, and (by design) Administrators are allowed to do that by default.","modified":"2026-08-12T03:51:29.897010735Z","published":"2023-06-13T00:00:00Z","database_specific":{"isDisputed":true,"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/30xxx/CVE-2023-30179.json","cna_assigner":"mitre"},"references":[{"type":"WEB","url":"https://datnlq.gitbook.io/cve/craft-cms/cve-2023-30179-server-side-template-injection"},{"type":"WEB","url":"https://github.com/craftcms/cms/blob/develop/CHANGELOG.md#442---2023-03-14"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/30xxx/CVE-2023-30179.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-30179"},{"type":"FIX","url":"https://github.com/github/advisory-database/pull/2443#issuecomment-1610040714"},{"type":"FIX","url":"https://github.com/github/advisory-database/pull/2443#issuecomment-1610634200"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/craftcms/cms","events":[{"introduced":"b3e6247db27b315615c02dad6dab89ecd9233d89"},{"last_affected":"b3e6247db27b315615c02dad6dab89ecd9233d89"}],"database_specific":{"cpe":"cpe:2.3:a:craftcms:craft_cms:3.7.59:*:*:*:*:*:*:*","extracted_events":[{"introduced":"3.7.59"},{"last_affected":"3.7.59"}],"source":"CPE_STRING"}}],"versions":["3.7.59"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-30179.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}