Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

ubuntu логотип

CVE-2022-21648

больше 4 лет назад

Latte is an open source template engine for PHP. Versions since 2.8.0 Latte has included a template sandbox and in affected versions it has been found that a sandbox escape exists allowing for injection into web pages generated from Latte. This may lead to XSS attacks. The issue is fixed in the versions 2.8.8, 2.9.6 and 2.10.8. Users unable to upgrade should not accept template input from untrusted sources.

CVSS3: 8.2
EPSS: Низкий
nvd логотип

CVE-2022-21648

больше 4 лет назад

Latte is an open source template engine for PHP. Versions since 2.8.0 Latte has included a template sandbox and in affected versions it has been found that a sandbox escape exists allowing for injection into web pages generated from Latte. This may lead to XSS attacks. The issue is fixed in the versions 2.8.8, 2.9.6 and 2.10.8. Users unable to upgrade should not accept template input from untrusted sources.

CVSS3: 8.2
EPSS: Низкий
debian логотип

CVE-2022-21648

больше 4 лет назад

Latte is an open source template engine for PHP. Versions since 2.8.0 ...

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-36m2-8rhx-f36j

больше 4 лет назад

Sandbox bypass in Latte templates

CVSS3: 8.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-21648

Latte is an open source template engine for PHP. Versions since 2.8.0 Latte has included a template sandbox and in affected versions it has been found that a sandbox escape exists allowing for injection into web pages generated from Latte. This may lead to XSS attacks. The issue is fixed in the versions 2.8.8, 2.9.6 and 2.10.8. Users unable to upgrade should not accept template input from untrusted sources.

CVSS3: 8.2
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2022-21648

Latte is an open source template engine for PHP. Versions since 2.8.0 Latte has included a template sandbox and in affected versions it has been found that a sandbox escape exists allowing for injection into web pages generated from Latte. This may lead to XSS attacks. The issue is fixed in the versions 2.8.8, 2.9.6 and 2.10.8. Users unable to upgrade should not accept template input from untrusted sources.

CVSS3: 8.2
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2022-21648

Latte is an open source template engine for PHP. Versions since 2.8.0 ...

CVSS3: 8.2
1%
Низкий
больше 4 лет назад
github логотип
GHSA-36m2-8rhx-f36j

Sandbox bypass in Latte templates

CVSS3: 8.2
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу