Описание
MJML prior to 4.6.3 contains a path traversal vulnerability when processing the mj-include directive within an MJML document.
Ссылки
- ExploitThird Party AdvisoryVDB Entry
- ExploitMailing ListThird Party Advisory
- PatchThird Party Advisory
- Release NotesThird Party Advisory
- Vendor Advisory
- Broken Link
- Third Party Advisory
- ExploitThird Party AdvisoryVDB Entry
- ExploitMailing ListThird Party Advisory
- PatchThird Party Advisory
- Release NotesThird Party Advisory
- Vendor Advisory
- Broken Link
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.6.3 (исключая)
cpe:2.3:a:mjml:mjml:*:*:*:*:*:*:*:*
EPSS
Процентиль: 85%
0.02387
Низкий
7.2 High
CVSS3
6.4 Medium
CVSS2
Дефекты
CWE-22
Связанные уязвимости
EPSS
Процентиль: 85%
0.02387
Низкий
7.2 High
CVSS3
6.4 Medium
CVSS2
Дефекты
CWE-22