Описание
Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats parameter.
Ссылки
- ExploitThird Party AdvisoryVDB Entry
- ExploitTechnical DescriptionThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- Technical Description
- ExploitThird Party AdvisoryVDB Entry
- ExploitTechnical DescriptionThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- Technical Description
Уязвимые конфигурации
Конфигурация 1Версия до 2.7.0 (включая)
cpe:2.3:a:tuzitio:camaleon_cms:*:*:*:*:*:*:*:*
EPSS
Процентиль: 98%
0.58834
Средний
9.8 Critical
CVSS3
Дефекты
CWE-94
CWE-94
Связанные уязвимости
EPSS
Процентиль: 98%
0.58834
Средний
9.8 Critical
CVSS3
Дефекты
CWE-94
CWE-94