Lucene search

K
osvGoogleOSV:CVE-2020-28468
HistoryJan 08, 2021 - 12:15 p.m.

CVE-2020-28468

2021-01-0812:15:12
Google
osv.dev
10
cve-2020-28468
pwntools
package
vulnerability
server-side template injection
ssti
remote code execution

AI Score

8.3

Confidence

Low

EPSS

0.033

Percentile

91.5%

This affects the package pwntools before 4.3.1. The shellcraft generator for affected versions of this module are vulnerable to Server-Side Template Injection (SSTI), which can lead to remote code execution.

AI Score

8.3

Confidence

Low

EPSS

0.033

Percentile

91.5%

Related for OSV:CVE-2020-28468