Lucene search

K
osvGoogleOSV:CVE-2020-28246
HistoryJun 02, 2022 - 2:15 p.m.

CVE-2020-28246

2022-06-0214:15:26
Google
osv.dev
5
server-side template injection
form.io 2.0.0
remote code execution
email template url
software

AI Score

9.9

Confidence

High

EPSS

0.005

Percentile

77.0%

A Server-Side Template Injection (SSTI) was discovered in Form.io 2.0.0. This leads to Remote Code Execution during deletion of the default Email template URL. NOTE: the email templating service was removed after 2020.

AI Score

9.9

Confidence

High

EPSS

0.005

Percentile

77.0%