Количество 4
Количество 4
CVE-2023-29827
ejs v3.1.9 is vulnerable to server-side template injection. If the ejs file is controllable, template injection can be implemented through the configuration settings of the closeDelimiter parameter. NOTE: this is disputed by the vendor because the render function is not intended to be used with untrusted input.
CVE-2023-29827
ejs v3.1.9 is vulnerable to server-side template injection. If the ejs file is controllable, template injection can be implemented through the configuration settings of the closeDelimiter parameter. NOTE: this is disputed by the vendor because the render function is not intended to be used with untrusted input.
CVE-2023-29827
ejs v3.1.9 is vulnerable to server-side template injection. If the ejs ...
GHSA-j5pp-6f4w-r5r6
ejs v3.1.9 is vulnerable to server-side template injection. If the ejs file is controllable, template injection can be implemented through the configuration settings of the closeDelimiter parameter.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2023-29827 ejs v3.1.9 is vulnerable to server-side template injection. If the ejs file is controllable, template injection can be implemented through the configuration settings of the closeDelimiter parameter. NOTE: this is disputed by the vendor because the render function is not intended to be used with untrusted input. | CVSS3: 9.8 | 81% Высокий | почти 3 года назад | |
CVE-2023-29827 ejs v3.1.9 is vulnerable to server-side template injection. If the ejs file is controllable, template injection can be implemented through the configuration settings of the closeDelimiter parameter. NOTE: this is disputed by the vendor because the render function is not intended to be used with untrusted input. | CVSS3: 9.8 | 81% Высокий | почти 3 года назад | |
CVE-2023-29827 ejs v3.1.9 is vulnerable to server-side template injection. If the ejs ... | CVSS3: 9.8 | 81% Высокий | почти 3 года назад | |
GHSA-j5pp-6f4w-r5r6 ejs v3.1.9 is vulnerable to server-side template injection. If the ejs file is controllable, template injection can be implemented through the configuration settings of the closeDelimiter parameter. | CVSS3: 9.8 | 81% Высокий | почти 3 года назад |
Уязвимостей на страницу