Cachet 2.4.1 Authenticated Server-Side Template Injection RCE
41Vexday Risk Score
Sin señal de explotación. Ella tiene prueba de concepto pública.
ssvc Attendcvss 8.7epss 0.6%
probabilidad de explotación
0.6%top 57% de las CVE
explotación observada
noninguna fuente lo reporta
1 exploit(s) público(s)
Cachet through 2.4.1 contains a server-side template injection vulnerability in incident template rendering that allows authenticated users to execute arbitrary PHP code. Attackers can create malicious incident templates with Blade directives or Twig filters that execute system commands when incidents are created, achieving remote code execution as the web server process.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
cachethq · cachetPoCs públicas encontradas — 1
cve_referencegithub.com/cachethq/cachet/issues/4621no verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.