High severity8.4NVD Advisory· Published Oct 6, 2023· Updated Jun 17, 2026
CVE-2023-45303
CVE-2023-45303
Description
ThingsBoard before 3.5 allows Server-Side Template Injection if users are allowed to modify an email template, because Apache FreeMarker supports freemarker.template.utility.Execute (for content sent to the /api/admin/settings endpoint).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.thingsboard:thingsboardMaven | < 3.5 | 3.5 |
Affected products
3cpe:2.3:a:thingsboard:thingsboard:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:thingsboard:thingsboard:*:*:*:*:*:*:*:*range: <3.5
- (no CPE)
Patches
Vulnerability mechanics
References
5- freemarker.apache.org/docs/api/freemarker/template/utility/Execute.htmlnvdExploitWEB
- herolab.usd.de/security-advisories/usd-2023-0010/nvdExploit
- github.com/advisories/GHSA-6pgr-j9v4-xfvvghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-45303ghsaADVISORY
- herolab.usd.de/security-advisories/usd-2023-0010ghsaWEB
News mentions
0No linked articles in our index yet.