Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-947q-2xw3-gx9c

Опубликовано: 12 дек. 2025
Источник: github
Github: Прошло ревью
CVSS4: 8.6

Описание

FoF Pretty Mail has a server-side template injection vulnerability

FoF Pretty Mail 1.1.2 contains a server-side template injection vulnerability that allows administrative users to inject malicious code into email templates. Attackers can execute system commands by inserting crafted template expressions that trigger arbitrary code execution during email generation.

Пакеты

Наименование

fof/pretty-mail

composer
Затронутые версииВерсия исправления

<= 1.1.2

Отсутствует

EPSS

Процентиль: 8%
0.0003
Низкий

8.6 High

CVSS4

Дефекты

CWE-1336

Связанные уязвимости

nvd
около 2 месяцев назад

FoF Pretty Mail 1.1.2 contains a server-side template injection vulnerability that allows administrative users to inject malicious code into email templates. Attackers can execute system commands by inserting crafted template expressions that trigger arbitrary code execution during email generation.

EPSS

Процентиль: 8%
0.0003
Низкий

8.6 High

CVSS4

Дефекты

CWE-1336