Critical severity9.8NVD Advisory· Published Aug 4, 2023· Updated Jun 17, 2026
CVE-2023-29689
CVE-2023-29689
Description
PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template injection (SSTI) flaw. This vulnerability allows a malicious attacker to send customized commands to the server and execute arbitrary code on the affected system.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
pyrocms/pyrocmsPackagist | <= 3.9 | — |
Affected products
3Patches
Vulnerability mechanics
References
4- cupc4k3.lol/ssti-leads-to-rce-on-pyrocms-7515be27c811nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-w7vm-4v3j-vgpwghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-29689ghsaADVISORY
- packetstormsecurity.com/files/174088/Pyro-CMS-3.9-Server-Side-Template-Injection.htmlnvdWEB
News mentions
0No linked articles in our index yet.