← Back to CVE List

CVE-2023-22621

Published: 2023-04-19T16:15Z
Last Modified: 2025-02-05T17:15Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Strapi through 4.5.5 allows authenticated Server-Side Template Injection (SSTI) that can be exploited to execute arbitrary code on the server. A remote attacker with access to the Strapi admin panel can inject a crafted payload that executes code on the server into an email template that bypasses the validation checks that should prevent code execution. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt