Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gf66-vvm8-54jq

Опубликовано: 27 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 4.8
CVSS3: 5.9

Описание

Agiloft Release 28 does not properly neutralize special elements used in an EUI template engine, allowing an authenticated attacker to achieve remote code execution by loading a specially crafted payload. Users should upgrade to Agiloft Release 31.

Agiloft Release 28 does not properly neutralize special elements used in an EUI template engine, allowing an authenticated attacker to achieve remote code execution by loading a specially crafted payload. Users should upgrade to Agiloft Release 31.

EPSS

Процентиль: 52%
0.00286
Низкий

4.8 Medium

CVSS4

5.9 Medium

CVSS3

Дефекты

CWE-1336

Связанные уязвимости

CVSS3: 5.9
nvd
5 месяцев назад

Agiloft Release 28 does not properly neutralize special elements used in an EUI template engine, allowing an authenticated attacker to achieve remote code execution by loading a specially crafted payload. Users should upgrade to Agiloft Release 31.

EPSS

Процентиль: 52%
0.00286
Низкий

4.8 Medium

CVSS4

5.9 Medium

CVSS3

Дефекты

CWE-1336