CyberSec.Space Logo
CVEブラウザに戻る

CVE-2020-21523

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.0840%
EPSS Percentile20.41th
Published2020年9月30日
Last Modified2024年11月21日

Vulnerability Description

A Server-Side Freemarker template injection vulnerability in halo CMS v1.1.3 In the Edit Theme File function. The ftl file can be edited. This is the Freemarker template file. This file can cause arbitrary code execution when it is rendered in the background. exp: <#assign test="freemarker.template.utility.Execute"?new()> ${test("touch /tmp/freemarkerPwned")}

Affected Platforms (CPE)

📦
Halo

Halo

= 1.1.3

References & Advisories

関連する脆弱性情報