Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-52vj-mr2j-f8jh

Опубликовано: 03 июн. 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Server-Side Template Injection in formio

A Server-Side Template Injection (SSTI) was discovered in Form.io 2.0.0. This leads to Remote Code Execution during deletion of the default Email template URL. NOTE: the email templating service was removed after 2020. Additionally, the vendor disputes this issue indicating this is sandboxed and only executable by admins.

Пакеты

Наименование

formio

npm
Затронутые версииВерсия исправления

<= 2.0.0

Отсутствует

EPSS

Процентиль: 87%
0.03455
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 9.8
nvd
больше 3 лет назад

A Server-Side Template Injection (SSTI) was discovered in Form.io 2.0.0. This leads to Remote Code Execution during deletion of the default Email template URL. NOTE: the email templating service was removed after 2020. Additionally, the vendor disputes this issue indicating this is sandboxed and only executable by admins.

EPSS

Процентиль: 87%
0.03455
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-74