Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-21648

Опубликовано: 04 янв. 2022
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 4.3
CVSS3: 8.2

Описание

Latte is an open source template engine for PHP. Versions since 2.8.0 Latte has included a template sandbox and in affected versions it has been found that a sandbox escape exists allowing for injection into web pages generated from Latte. This may lead to XSS attacks. The issue is fixed in the versions 2.8.8, 2.9.6 and 2.10.8. Users unable to upgrade should not accept template input from untrusted sources.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
esm-apps/bionic

needs-triage

esm-apps/xenial

needs-triage

trusty

ignored

end of standard support
upstream

needs-triage

xenial

ignored

end of standard support

Показывать по

EPSS

Процентиль: 54%
0.00311
Низкий

4.3 Medium

CVSS2

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 8.2
nvd
около 4 лет назад

Latte is an open source template engine for PHP. Versions since 2.8.0 Latte has included a template sandbox and in affected versions it has been found that a sandbox escape exists allowing for injection into web pages generated from Latte. This may lead to XSS attacks. The issue is fixed in the versions 2.8.8, 2.9.6 and 2.10.8. Users unable to upgrade should not accept template input from untrusted sources.

CVSS3: 8.2
debian
около 4 лет назад

Latte is an open source template engine for PHP. Versions since 2.8.0 ...

CVSS3: 8.2
github
около 4 лет назад

Sandbox bypass in Latte templates

EPSS

Процентиль: 54%
0.00311
Низкий

4.3 Medium

CVSS2

8.2 High

CVSS3