S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated May 26, 2024

CVE-2024-32651 Scanner

CVE-2024-32651 scanner - Server Side Template Injection (SSTI) vulnerability in Change Detection

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.6k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-32651
10.0
CVSScritical
Exploitable remotely over the internet · no authentication required.

changedetection.io is an open source web page change detection, website watcher, restock monitor and notification service. There is a Server Side Template Injection (SSTI) in Jinja2 that allows Remote Command Execution on the server host. Attackers can run any system command without any restriction and they could use a reverse shell. The impact is critical as the attacker can completely takeover the server machine. This can be reduced if changedetection is behind a login page, but this isn't required by the application (not by default and not enforced).

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
changedetection.ioby dgtlmoon
<= 0.45.20
changedetection.ioby dgtlmoon
0.45.20
Updated Aug 22, 2026View on NVD →
Detail

Change Detection is a tool used to monitor websites for changes. It is primarily utilized by businesses and individuals to keep track of content updates on webpages. Users can be notified of changes via email or other means. The software allows for tracking changes in a variety of formats including text and images. Change Detection is popular for monitoring competitor websites, tracking news articles, and observing changes in online documentation.

The vulnerability in Change Detection is a Server Side Template Injection (SSTI). It arises from the unsafe use of Jinja2 template functions. This flaw allows an attacker to execute arbitrary commands on the server hosting the application. The vulnerability is critical, with a CVSS score of 10, indicating high potential for exploitation and severe impact.

The Server Side Template Injection (SSTI) vulnerability in Change Detection occurs due to the insecure handling of Jinja2 template functions. An attacker can inject malicious payloads into the template rendering process, leading to remote command execution on the server. The vulnerable endpoint is the main page where templates are processed. This issue affects versions of Change Detection up to and including 0.45.20. Successful exploitation can grant attackers control over the server.

Exploitation of this vulnerability can lead to severe consequences, including remote command execution on the server. Attackers could potentially gain unauthorized access to sensitive data, modify website content, and take control of the server's resources. This can result in data breaches, service disruptions, and further attacks on connected systems. The critical nature of this vulnerability means it poses a significant risk to the integrity and security of the affected systems.

Join the S4E platform to safeguard your digital assets with our comprehensive Cyber Threat Exposure Management service. Our advanced scanners detect and report critical vulnerabilities like Server Side Template Injection (SSTI) in Change Detection, helping you stay ahead of potential threats. With S4E, you'll benefit from regular updates, detailed reports, and expert advice on mitigating risks. Protect your business and ensure your systems are secure by becoming a member today.

References:

Solution Advice
  • Update Change Detection to the latest version where the vulnerability is fixed.
  • Review and secure template rendering processes to avoid the use of unsafe functions.
  • Implement input validation and sanitization to prevent injection attacks.
  • Regularly audit and test your applications for security vulnerabilities.
  • Follow security best practices for server configuration and access control.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.