Back to directory
WRITEUP #66

WPML Multilingual CMS Authenticated Contributor+ Remote Code Execution (RCE) via Twig Server-Side Template Injection (SSTI)

RCESSTISecurity code review
by@stealthcopter(Matthew Rollings)
Bounty
1,639
Program
Wordfence
Published
Aug 21, 2024
Added to HackDex
Aug 22, 2024
Read Full Writeuphttps://sec.stealthcopter.com/wpml-rce-via-twig-ssti/
RELATED WRITEUPS
Chaining Three Bugs to Access All Your ServiceNow Data
RCESSTI
Getting code execution on Veeam through CVE-2023-27532
RCEInsecure deserialization
Spip Preauth RCE 2024: Part 2, A Big Upload
RCEFile upload
Back To School - Exploiting A Remote Code Execution Vulnerability In Moodle
RCESecurity code review
WordPress GiveWP POP to RCE (CVE-2024-5932)
RCEPHP pop chain

Built with ❤️ by Shubham Rawat