Lucene search

K
prionPRIOn knowledge basePRION:CVE-2024-22533
HistoryFeb 02, 2024 - 3:15 a.m.

Sql injection

2024-02-0203:15:00
PRIOn knowledge base
www.prio-n.com
3
sql injection
server-side template injection
ssti vulnerability
code execution
security document
nvd

8 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

50.7%

Before Beetl v3.15.12, the rendering template has a server-side template injection (SSTI) vulnerability. When the incoming template is controllable, it will be filtered by the DefaultNativeSecurityManager blacklist. Because blacklist filtering is not strict, the blacklist can be bypassed, leading to arbitrary code execution.

CPENameOperatorVersion
beetleq3.15.12

8 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

50.7%

Related for PRION:CVE-2024-22533