7.2
CVSSv3

CVE-2020-25803

Published: 06/10/2020 Updated: 09/10/2020
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via FreeMarker template exposed objects. This issue affects: Crafter Software Crafter CMS 3.0 versions before 3.0.27; 3.1 versions before 3.1.7.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

craftercms studio

Github Repositories

CVE-2022-40634: FreeMarker Server-Side Template Injection in CrafterCMS

CVE-2022-40634: FreeMarker Server-Side Template Injection in CrafterCMS By inserting malicious content in a FTL template, an attacker may perform SSTI (Server-Side Template Injection) attacks, which can leverage FreeMarker exposed objects to bypass restrictions and obtain RCE (Remote Code Execution) Vendor Disclosure: The vendor's disclosure and fix for this vulnerability