Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:25169
HistoryMay 05, 2020 - 10:35 a.m.

Server-Side Template Injection

2020-05-0510:35:33
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10

0.002 Low

EPSS

Percentile

59.4%

syncope-client-console is vulnerable to server-side template injection. The attack is possible because it uses different types of interpolation, such as Java EL expressions for handling custom constrain violation error messages during building of Java Bean Validation custom constraint validators.Therefore, an attacker can inject malicious data using the error message template being passed, leading to a remote code execution.

0.002 Low

EPSS

Percentile

59.4%

Related for VERACODE:25169