Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:25158
HistoryMay 04, 2020 - 5:58 a.m.

Server-Side Template Injection

2020-05-0405:58:47
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

0.001 Low

EPSS

Percentile

43.1%

syncope-core-provisioning-java is vulnerable to server-side template injection. Remote attackers are able to inject arbitrary JEXL expressions via the Mail templates and execute arbitrary code on the system.

0.001 Low

EPSS

Percentile

43.1%

Related for VERACODE:25158