Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-71456
HistoryAug 18, 2021 - 12:00 a.m.

TryGhost express-hbs information disclosure vulnerability

2021-08-1800:00:00
China National Vulnerability Database
www.cnvd.org.cn
6

0.002 Low

EPSS

Percentile

60.4%

TryGhost express-hbs is an Express handlebar template engine with multiple layouts, blocks and cache sections. tryGhost express-hbs suffers from an information disclosure vulnerability that stems from the product’s Express render API mixing pure template data with engine configuration options, which can be exploited by an attacker to override internal configuration options resulting in a file leak.

0.002 Low

EPSS

Percentile

60.4%