THREAT OPS › Threat News › [GHSA] GHSA-f5wm-88jv-g5hx (high) — Craft CMS: Authenticated RCE through Twig sandbox escape
[GHSA] GHSA-f5wm-88jv-g5hx (high) — Craft CMS: Authenticated RCE through Twig sandbox escape
GHSA-f5wm-88jv-g5hx Severity: high CVE: None
Craft CMS: Authenticated RCE through Twig sandbox escape
The Twig sandbox mechanism in Craft CMS is configured to allow dangerous functionality from the Yii framework, leading to authenticated RCE in a manner similar to previously disclosed vulnerabilities.
The Twig sandbox in Craft CMS works by implementing Twig's `SecurityPolicyInterface`. The resu
MITRE ATT&CK techniques
Original source: https://github.com/advisories/GHSA-f5wm-88jv-g5hx