Product
A Server-Side Template Injection (SSTI) vulnerability in Mautic's theme engine allows authenticated users with theme creation or upload privileges to execute arbitrary system commands (Remote Code Execution) and access restricted system files on the hosting server, due to the platform rendering uploaded Twig templates without a sandbox or strict function restrictions.