---
id: CVE-2024-58303
title: >-
  FoF Pretty Mail 1.1.2 contains a server-side template injection vulnerability
  that allows administrative users to inject malicious code into email templates
summary: >-
  FoF Pretty Mail 1.1.2 contains a server-side template injection vulnerability
  that allows administrative users to inject malicious code into email
  templates. Attackers can execute system commands by inserting crafted template
  expressions…
severity: high
cvss: 8.6
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-1336
vendor: Flarum
product: FriendsofFlarum Pretty Mail
affected:
  - friendsofflarum_pretty_mail 1.1.2
published: '2025-12-11'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:16:49.313'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-58303'
references:
  - url: 'https://flarum.org/'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/FriendsOfFlarum/pretty-mail'
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/51948'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/fof-pretty-mail-server-side-template-injection-via-email-template-settings
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2025-12-18T21:35:25.679403Z'
cvssSource: cna
epss: 0.00539
epssPercentile: 0.43552
ingestedAt: '2026-10-08T16:52:14.666Z'
---

## Overview

FoF Pretty Mail 1.1.2 contains a server-side template injection vulnerability that allows administrative users to inject malicious code into email templates. Attackers can execute system commands by inserting crafted template expressions that trigger arbitrary code execution during email generation.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
