Логотип exploitDog
bind:CVE-2020-28246
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-28246

Количество 2

Количество 2

nvd логотип

CVE-2020-28246

больше 3 лет назад

A Server-Side Template Injection (SSTI) was discovered in Form.io 2.0.0. This leads to Remote Code Execution during deletion of the default Email template URL. NOTE: the email templating service was removed after 2020. Additionally, the vendor disputes this issue indicating this is sandboxed and only executable by admins.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-52vj-mr2j-f8jh

больше 3 лет назад

Server-Side Template Injection in formio

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-28246

A Server-Side Template Injection (SSTI) was discovered in Form.io 2.0.0. This leads to Remote Code Execution during deletion of the default Email template URL. NOTE: the email templating service was removed after 2020. Additionally, the vendor disputes this issue indicating this is sandboxed and only executable by admins.

CVSS3: 9.8
3%
Низкий
больше 3 лет назад
github логотип
GHSA-52vj-mr2j-f8jh

Server-Side Template Injection in formio

CVSS3: 9.8
3%
Низкий
больше 3 лет назад

Уязвимостей на страницу