vendor:
MotoCMS
by:
tmrswrr
7.5
CVSS
HIGH
Server-Side Template Injection (SSTI)
79
CWE
Product Name: MotoCMS
Affected Version From: MotoCMS 3.0.27
Affected Version To: MotoCMS 3.4.3
Patch Exists: NO
Related CWE:
CPE: a:motocms:motocms:3.4.3
Platforms Tested:
2023
MotoCMS Version 3.4.3 โ Server-Side Template Injection (SSTI)
MotoCMS Version 3.4.3 Store Category Template was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the keyword parameter.
Mitigation:
Apply the latest patch or update to the non-vulnerable version of MotoCMS.