VYPR
High severity8.4NVD Advisory· Published Oct 6, 2023· Updated Jun 17, 2026

CVE-2023-45303

CVE-2023-45303

Description

ThingsBoard before 3.5 allows Server-Side Template Injection if users are allowed to modify an email template, because Apache FreeMarker supports freemarker.template.utility.Execute (for content sent to the /api/admin/settings endpoint).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.thingsboard:thingsboardMaven
< 3.53.5

Affected products

3

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.