Security Advisory

CVE-2018-19907

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-12-06 07:00:00
Last updated 2024-08-05 11:51:17
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

A Server-Side Template Injection issue was discovered in Crafter CMS 3.0.18. Attackers with developer privileges may execute OS commands by Creating/Editing a template file (.ftl filetype) that triggers a call to freemarker.template.utility.Execute in the FreeMarker library during rendering of a web page.