CVE-2024-58303

Source
https://cve.org/CVERecord?id=CVE-2024-58303
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-58303.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-58303
Aliases
Published
2025-12-11T21:40:26.839Z
Modified
2026-08-12T03:51:28.307075568Z
Severity
  • 8.6 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
FoF Pretty Mail 1.1.2 Server Side Template Injection via Email Template Settings
Details

FoF Pretty Mail 1.1.2 contains a server-side template injection vulnerability that allows administrative users to inject malicious code into email templates. Attackers can execute system commands by inserting crafted template expressions that trigger arbitrary code execution during email generation.

Database specific
{
    "cwe_ids": [
        "CWE-1336"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/58xxx/CVE-2024-58303.json",
    "cna_assigner": "VulnCheck"
}
References

Affected packages

Git / github.com/friendsofflarum/pretty-mail

Affected ranges

Type
GIT
Repo
https://github.com/friendsofflarum/pretty-mail
Events
Database specific
Show details
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "1.1.2"
        },
        {
            "last_affected": "1.1.2"
        }
    ]
}

Affected versions

1.*
1.1.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-58303.json"