References https://nvd.nist.gov/vuln/detail/CVE-2023-43661 https://github.com/cachethq/cachet/security/advisories/GHSA-hv79-p62r-wg3p https://github.com/advisories/GHSA-hv79-p62r-wg3p https://www.miggo.io/vulnerability-database/cve/CVE-2023-43661 https://research.vulmon.com/vuln/CVE-2023-43661 https://www.juniper.net/us/en/threatlabs/ips-signatures/detail.HTTP:CTS:CACHET-HQ-TEMP-INJ.html https://www.trendmicro.com/vinfo/us/threat-encyclopedia/vulnerability/8788/23-052-november-21-2023 https://update.nsfocusglobal.com/update/listNewipsDetail/v/rule5.6.11
Related VulnerabilitiesPoCCVE-2026-42461: Arcane < 1.18.0 - Unauthenticated Template and Env DisclosureArcane /api/templates 未授权访问漏洞(CVE-2026-42461)PoCCVE-2026-28496: FOSSBilling - Server-Side Template Injection智邦国际ERP /SYSN/json/pcclient/GetAllPrintTemplate.ashx SQL 注入漏洞索贝 template/api/styleList/3 未授权访问漏洞天地伟业 Easy7 /Easy7/rest/preSetTemplate/getRecByTemplateId SQL 注入漏洞用友政务财务系统 /billdesigner/office/downloadTemplate 文件读取漏洞PoCCVE-2021-23337: Lodash Template - Server-Side Template Injection (RCE)PoCCVE-2026-4257: WordPress Contact Form by Supsystic - Server-Side Template InjectionPoC宏景系统 /templates/attestation/../../servlet/performance/fileDownLoad SQL 注入漏洞天锐绿盾审批系统 /trwfe/login.jsp/.%2e/rest/ext/template 命令执行漏洞宏景eHR /templates/attestation/../../jp_contest/personinfo/ShowStuffInfo SQL 注入漏洞