Cachet vulnerable to Authenticated Remote Code Execution
CVE-2023-43661
8.8HIGH
What is CVE-2023-43661?
A critical vulnerability in Cachet, the open-source status page system, allows an attacker to execute arbitrary code on the server due to a flaw in the template functionality. This issue arises from inadequate input filtration and the use of an outdated version of the Twig templating engine. Users of Cachet prior to the 2.4 branch are particularly at risk. A patch addressing this vulnerability has been offered in commit 6fb043e109d2a262ce3974e863c54e9e5f5e0587.
Affected Version(s)
cachet < 2.4
References
EPSS Score
46% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
