Описание
A Server-Side Template Injection (SSTI) vulnerability in the Registration and Forgotten Password forms of Magnolia v6.2.3 and below allows attackers to execute arbitrary code via a crafted payload entered into the fullname parameter.
Ссылки
- Release NotesVendor Advisory
- ExploitThird Party Advisory
- Release NotesVendor Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 6.2.4 (исключая)
cpe:2.3:a:magnolia-cms:magnolia_cms:*:*:*:*:*:*:*:*
EPSS
Процентиль: 86%
0.02924
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-94
Связанные уязвимости
CVSS3: 9.8
github
почти 4 года назад
A Server-Side Template Injection (SSTI) vulnerability in the Registration and Forgotten Password forms of Magnolia v6.2.3 and below allows attackers to execute arbitrary code via a crafted payload entered into the fullname parameter.
EPSS
Процентиль: 86%
0.02924
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-94