VYPR

npm package

@strapi/plugin-email

pkg:npm/%40strapi/plugin-email

Vulnerabilities (1)

  • CVE-2023-22621Apr 19, 2023
    affected < 4.5.6fixed 4.5.6

    Strapi through 4.5.5 allows authenticated Server-Side Template Injection (SSTI) that can be exploited to execute arbitrary code on the server. A remote attacker with access to the Strapi admin panel can inject a crafted payload that executes code on the server into an email templ