Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:7014
HistoryJul 11, 2018 - 5:24 a.m.

Server-Side Template Injection (SSTI)

2018-07-1105:24:19
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10

EPSS

0.06

Percentile

93.5%

twig/twig is vulnerable to server-side template injection (SSTI) attacks. The vulnerabiltiy exists due to the way twig/twig interprets the value of the token in the templates, allowing commands to be executed depending on the vulnerable application.

EPSS

0.06

Percentile

93.5%