NA

CVE-2022-40634

Published: 13/09/2022 Updated: 16/09/2022
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 0

Vulnerability Summary

Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via FreeMarker SSTI.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

craftercms crafter cms

Github Repositories

CVE-2022-40634: FreeMarker Server-Side Template Injection in CrafterCMS

CVE-2022-40634: FreeMarker Server-Side Template Injection in CrafterCMS By inserting malicious content in a FTL template, an attacker may perform SSTI (Server-Side Template Injection) attacks, which can leverage FreeMarker exposed objects to bypass restrictions and obtain RCE (Remote Code Execution) Vendor Disclosure: The vendor's disclosure and fix for this vulnerability