Cachet vulnerable to Authenticated Remote Code Execution
CVE-2023-43661

8.8HIGH

Key Information:

Vendor

cachethq

Status
Vendor
CVE Published:
11 October 2023

What is CVE-2023-43661?

A critical vulnerability in Cachet, the open-source status page system, allows an attacker to execute arbitrary code on the server due to a flaw in the template functionality. This issue arises from inadequate input filtration and the use of an outdated version of the Twig templating engine. Users of Cachet prior to the 2.4 branch are particularly at risk. A patch addressing this vulnerability has been offered in commit 6fb043e109d2a262ce3974e863c54e9e5f5e0587.

Affected Version(s)

cachet < 2.4

References

EPSS Score

46% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.