Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mx65-vqhq-g7wg

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A Server-Side Freemarker template injection vulnerability in halo CMS v1.1.3 In the Edit Theme File function. The ftl file can be edited. This is the Freemarker template file. This file can cause arbitrary code execution when it is rendered in the background. exp: <#assign test="freemarker.template.utility.Execute"?new()> ${test("touch /tmp/freemarkerPwned")}

A Server-Side Freemarker template injection vulnerability in halo CMS v1.1.3 In the Edit Theme File function. The ftl file can be edited. This is the Freemarker template file. This file can cause arbitrary code execution when it is rendered in the background. exp: <#assign test="freemarker.template.utility.Execute"?new()> ${test("touch /tmp/freemarkerPwned")}

EPSS

Процентиль: 74%
0.00837
Низкий

Связанные уязвимости

CVSS3: 9.8
nvd
больше 5 лет назад

A Server-Side Freemarker template injection vulnerability in halo CMS v1.1.3 In the Edit Theme File function. The ftl file can be edited. This is the Freemarker template file. This file can cause arbitrary code execution when it is rendered in the background. exp: <#assign test="freemarker.template.utility.Execute"?new()> ${test("touch /tmp/freemarkerPwned")}

EPSS

Процентиль: 74%
0.00837
Низкий