A Server-Side Freemarker template injection vulnerability in halo CMS v1.1.3 In the Edit Theme File function. The ftl file can be edited. This is the Freemarker template file. This file can cause arbitrary code execution when it is rendered in the background. exp: <#assign test="freemarker.template.utility.Execute"?new()> ${test("touch /tmp/freemarkerPwned")}
References
Link | Resource |
---|---|
https://github.com/halo-dev/halo/issues/419 | Exploit Issue Tracking Third Party Advisory |
Configurations
Information
Published : 2020-09-30 11:15
Updated : 2020-10-09 10:40
NVD link : CVE-2020-21523
Mitre link : CVE-2020-21523
JSON object : View
CWE
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
Products Affected
halo
- halo