PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template injection (SSTI) flaw. This vulnerability allows a malicious attacker to send customized commands to the server and execute arbitrary code on the affected system.
{
"cwe_ids": [],
"github_reviewed": true,
"github_reviewed_at": "2023-08-04T17:27:09Z",
"nvd_published_at": "2023-08-04T15:15:10Z",
"severity": "CRITICAL"
}