CVE-2023-22621

Severity CVSS v4.0:
Pending analysis
Type:
CWE-74 Injection
Publication date:
19/04/2023
Last modified:
07/11/2025

Description

Strapi through 4.5.5 allows authenticated Server-Side Template Injection (SSTI) that can be exploited to execute arbitrary code on the server. A remote attacker with access to the Strapi admin panel can inject a crafted payload that executes code on the server into an email template that bypasses the validation checks that should prevent code execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:strapi:strapi:*:*:*:*:*:*:*:* 3.0.0 (including) 4.5.6 (excluding)