Логотип exploitDog
bind:CVE-2024-37301
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-37301

Количество 2

Количество 2

nvd логотип

CVE-2024-37301

больше 1 года назад

Document Merge Service is a document template merge service providing an API to manage templates and merge them with given data. Versions 6.5.1 and prior are vulnerable to remote code execution via server-side template injection which, when executed as root, can result in full takeover of the affected system. As of time of publication, no patched version exists, nor have any known workarounds been disclosed.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-v5gf-r78h-55q6

больше 1 года назад

document-merge-service vulnerable to Remote Code Execution via Server-Side Template Injection

CVSS3: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-37301

Document Merge Service is a document template merge service providing an API to manage templates and merge them with given data. Versions 6.5.1 and prior are vulnerable to remote code execution via server-side template injection which, when executed as root, can result in full takeover of the affected system. As of time of publication, no patched version exists, nor have any known workarounds been disclosed.

CVSS3: 7.2
6%
Низкий
больше 1 года назад
github логотип
GHSA-v5gf-r78h-55q6

document-merge-service vulnerable to Remote Code Execution via Server-Side Template Injection

CVSS3: 7.2
6%
Низкий
больше 1 года назад

Уязвимостей на страницу