A Server-side Template Injection (SSTI) vulnerability exists in bbs 5.3 in TemplateManageAction.javawhich could let a malicoius user execute arbitrary code.
References
Link | Resource |
---|---|
https://github.com/diyhi/bbs/issues/51 | Exploit Issue Tracking Third Party Advisory |
Configurations
Information
Published : 2022-03-28 15:15
Updated : 2022-07-12 10:42
NVD link : CVE-2021-43097
Mitre link : CVE-2021-43097
JSON object : View
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
Products Affected
diyhi
- bbs