Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:31813
HistoryAug 25, 2021 - 3:16 a.m.

Template Injection

2021-08-2503:16:29
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5
hbs
template injection
express render api
file viewing
configuration options

EPSS

0.002

Percentile

60.4%

hbs is vulnerable to template injection. The vulnerability exists due to a lack of sanitization of configuration options when input into the system via the Express render API. An attacker is able to view a file by overwriting an internal configuration option.

EPSS

0.002

Percentile

60.4%