CVE-2023-45303

Severity CVSS v4.0:
Pending analysis
Type:
CWE-74 Injection
Publication date:
06/10/2023
Last modified:
19/09/2024

Description

ThingsBoard before 3.5 allows Server-Side Template Injection if users are allowed to modify an email template, because Apache FreeMarker supports freemarker.template.utility.Execute (for content sent to the /api/admin/settings endpoint).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:thingsboard:thingsboard:*:*:*:*:*:*:*:* 3.5 (excluding)