← Back to browse · API

CVE-2023-22621

Severity
CRITICAL
CVSS
10.0
EPSS
0.76825
Risk score
66.89
CISA KEV
No
PoC
No
Published
2023-04-19
Modified
2025-11-07
First seen
2026-08-07
Aliases
EUVD-2023-1157, GHSA-2H87-4Q2W-V4HF
Products
n/a:n/a n/a
Sources
euvd EUVD-2023-1157

Description

Strapi through 4.5.5 allows authenticated Server-Side Template Injection (SSTI) that can be exploited to execute arbitrary code on the server. A remote attacker with access to the Strapi admin panel can inject a crafted payload that executes code on the server into an email template that bypasses the validation checks that should prevent code execution.

References