Motocms version 3.4.3 serverside template injection (ssti) Vulnerability / Exploit
/
/
/
Exploits / Vulnerability Discovered : 2023-05-31 |
Type : webapps |
Platform : multiple
This exploit / vulnerability Motocms version 3.4.3 serverside template injection (ssti) is for educational purposes only and if it is used you will do on your own risk!
## Description
MotoCMS Version 3.4.3 Store Category Template was discovered to contain a Server-Side Template
Injection (SSTI) vulnerability via the keyword parameter.
## Steps to Reproduce
1. Open the target URL: https://template189526.motopreview.com/
2. Write payload here : https://template189526.motopreview.com/store/category/search/?page=1&limit=36&keyword={{7*7}}
3. You will be see result is 49