Логотип exploitDog
bind:CVE-2022-21648
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-21648

Количество 4

Количество 4

ubuntu логотип

CVE-2022-21648

около 4 лет назад

Latte is an open source template engine for PHP. Versions since 2.8.0 Latte has included a template sandbox and in affected versions it has been found that a sandbox escape exists allowing for injection into web pages generated from Latte. This may lead to XSS attacks. The issue is fixed in the versions 2.8.8, 2.9.6 and 2.10.8. Users unable to upgrade should not accept template input from untrusted sources.

CVSS3: 8.2
EPSS: Низкий
nvd логотип

CVE-2022-21648

около 4 лет назад

Latte is an open source template engine for PHP. Versions since 2.8.0 Latte has included a template sandbox and in affected versions it has been found that a sandbox escape exists allowing for injection into web pages generated from Latte. This may lead to XSS attacks. The issue is fixed in the versions 2.8.8, 2.9.6 and 2.10.8. Users unable to upgrade should not accept template input from untrusted sources.

CVSS3: 8.2
EPSS: Низкий
debian логотип

CVE-2022-21648

около 4 лет назад

Latte is an open source template engine for PHP. Versions since 2.8.0 ...

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-36m2-8rhx-f36j

около 4 лет назад

Sandbox bypass in Latte templates

CVSS3: 8.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-21648

Latte is an open source template engine for PHP. Versions since 2.8.0 Latte has included a template sandbox and in affected versions it has been found that a sandbox escape exists allowing for injection into web pages generated from Latte. This may lead to XSS attacks. The issue is fixed in the versions 2.8.8, 2.9.6 and 2.10.8. Users unable to upgrade should not accept template input from untrusted sources.

CVSS3: 8.2
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-21648

Latte is an open source template engine for PHP. Versions since 2.8.0 Latte has included a template sandbox and in affected versions it has been found that a sandbox escape exists allowing for injection into web pages generated from Latte. This may lead to XSS attacks. The issue is fixed in the versions 2.8.8, 2.9.6 and 2.10.8. Users unable to upgrade should not accept template input from untrusted sources.

CVSS3: 8.2
0%
Низкий
около 4 лет назад
debian логотип
CVE-2022-21648

Latte is an open source template engine for PHP. Versions since 2.8.0 ...

CVSS3: 8.2
0%
Низкий
около 4 лет назад
github логотип
GHSA-36m2-8rhx-f36j

Sandbox bypass in Latte templates

CVSS3: 8.2
0%
Низкий
около 4 лет назад

Уязвимостей на страницу