Логотип exploitDog
bind:CVE-2022-24881
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-24881

Количество 2

Количество 2

nvd логотип

CVE-2022-24881

почти 4 года назад

Ballcat Codegen provides the function of online editing code to generate templates. In versions prior to 1.0.0.beta.2, attackers can implement remote code execution through malicious code injection of the template engine. This happens because Velocity and freemarker templates are introduced but input verification is not done. The fault is rectified in version 1.0.0.beta.2.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-fv3m-xhqw-9m79

почти 4 года назад

ballcat-codegen template engine remote code execution injection

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-24881

Ballcat Codegen provides the function of online editing code to generate templates. In versions prior to 1.0.0.beta.2, attackers can implement remote code execution through malicious code injection of the template engine. This happens because Velocity and freemarker templates are introduced but input verification is not done. The fault is rectified in version 1.0.0.beta.2.

CVSS3: 8.8
5%
Низкий
почти 4 года назад
github логотип
GHSA-fv3m-xhqw-9m79

ballcat-codegen template engine remote code execution injection

CVSS3: 8.8
5%
Низкий
почти 4 года назад

Уязвимостей на страницу