Логотип exploitDog
bind:CVE-2024-29686
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-29686

Количество 2

Количество 2

nvd логотип

CVE-2024-29686

почти 2 года назад

Server-side Template Injection (SSTI) vulnerability in Winter CMS v.1.2.3 allows a remote attacker to execute arbitrary code via a crafted payload to the CMS Pages field and Plugin components. NOTE: the vendor disputes this because the payload could only be entered by a trusted user, such as the owner of the server that hosts Winter CMS, or a developer working for them.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-8r5j-gm3j-cx9c

почти 2 года назад

Winter CMS Server-Side Template Injection (SSTI) vulnerability

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-29686

Server-side Template Injection (SSTI) vulnerability in Winter CMS v.1.2.3 allows a remote attacker to execute arbitrary code via a crafted payload to the CMS Pages field and Plugin components. NOTE: the vendor disputes this because the payload could only be entered by a trusted user, such as the owner of the server that hosts Winter CMS, or a developer working for them.

CVSS3: 7.2
3%
Низкий
почти 2 года назад
github логотип
GHSA-8r5j-gm3j-cx9c

Winter CMS Server-Side Template Injection (SSTI) vulnerability

CVSS3: 8.8
3%
Низкий
почти 2 года назад

Уязвимостей на страницу