Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7747-6373-9653

Опубликовано: 18 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

A Server-Side Template Injection (SSTI) vulnerability in the Velocity template engine configuration of xdocreport v0.9.2 to v2.2.0 allows attackers to execute arbitrary code via a crafted expression.

A Server-Side Template Injection (SSTI) vulnerability in the Velocity template engine configuration of xdocreport v0.9.2 to v2.2.0 allows attackers to execute arbitrary code via a crafted expression.

EPSS

Процентиль: 19%
0.00271
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-94

Связанные уязвимости

nvd
1 день назад

A Server-Side Template Injection (SSTI) vulnerability in the Velocity template engine configuration of xdocreport v0.9.2 to v2.2.0 allows attackers to execute arbitrary code via a crafted expression.

debian
1 день назад

A Server-Side Template Injection (SSTI) vulnerability in the Velocity ...

EPSS

Процентиль: 19%
0.00271
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-94