Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9hp3-f5g8-rccg

Опубликовано: 27 авг. 2025
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

The Freeform CraftCMS plugin contains an Server-side template injection (SSTI) vulnerability

Freeform 5.0.0 to before 5.10.16, a plugin for CraftCMS, contains an Server-side template injection (SSTI) vulnerability, resulting in arbitrary code injection for all users that have access to editing a form (submission title).

Пакеты

Наименование

solspace/craft-freeform

composer
Затронутые версииВерсия исправления

>= 5.0.0, < 5.10.16

5.10.16

EPSS

Процентиль: 24%
0.00083
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 9.8
nvd
6 месяцев назад

Freeform 5.0.0 to before 5.10.16, a plugin for CraftCMS, contains an Server-side template injection (SSTI) vulnerability, resulting in arbitrary code injection for all users that have access to editing a form (submission title).

EPSS

Процентиль: 24%
0.00083
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-94