Описание
A Server-Side Template Injection (SSTI) vulnerability in the Velocity template engine configuration of xdocreport v0.9.2 to v2.2.0 allows attackers to execute arbitrary code via a crafted expression.
EPSS
Процентиль: 19%
0.00271
Низкий
Дефекты
Связанные уязвимости
debian
1 день назад
A Server-Side Template Injection (SSTI) vulnerability in the Velocity ...
CVSS3: 9.8
github
1 день назад
A Server-Side Template Injection (SSTI) vulnerability in the Velocity template engine configuration of xdocreport v0.9.2 to v2.2.0 allows attackers to execute arbitrary code via a crafted expression.
EPSS
Процентиль: 19%
0.00271
Низкий