Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-37301

Опубликовано: 11 июн. 2024
Источник: nvd
CVSS3: 7.2
EPSS Низкий

Описание

Document Merge Service is a document template merge service providing an API to manage templates and merge them with given data. Versions 6.5.1 and prior are vulnerable to remote code execution via server-side template injection which, when executed as root, can result in full takeover of the affected system. As of time of publication, no patched version exists, nor have any known workarounds been disclosed.

EPSS

Процентиль: 90%
0.05604
Низкий

7.2 High

CVSS3

Дефекты

CWE-1336

Связанные уязвимости

CVSS3: 7.2
github
больше 1 года назад

document-merge-service vulnerable to Remote Code Execution via Server-Side Template Injection

EPSS

Процентиль: 90%
0.05604
Низкий

7.2 High

CVSS3

Дефекты

CWE-1336