Description
FoF Pretty Mail 1.1.2 contains a server-side template injection vulnerability that allows administrative users to inject malicious code into email templates. Attackers can execute system commands by inserting crafted template expressions that trigger arbitrary code execution during email generation.
Problem types
CWE-1336: Improper Neutralization of Special Elements Used in a Template Engine (SSTI)
Product status
1.1.2
Credits
Chokri Hammedi, <chokri.hammedi@unknown>
References
www.exploit-db.com/exploits/51948 (ExploitDB-51948)
flarum.org/ (Flarum Homepage)
github.com/FriendsOfFlarum/pretty-mail (Pretty Mail GitHub Repository)
www.vulncheck.com/...e-injection-via-email-template-settings (VulnCheck Advisory: FoF Pretty Mail 1.1.2 Server Side Template Injection via Email Template Settings)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.