← voltar
CVE-2025-12107highCWE-1336

Potential authenticated Server-Side Template Injection (SSTI) vulnerability.

21Vexday Risk Score

Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.

ssvc Trackcvss 8.4epss 0.6%
probabilidade de exploração
0.6%top 54% das CVEs
exploração observada
nãonenhuma fonte reporta
Due to the use of a vulnerable third-party Velocity template engine, a malicious actor with admin privilege may inject and execute arbitrary template syntax within server-side templates. Successful exploitation of this vulnerability could allow a malicious actor with admin privilege to inject and execute arbitrary template code on the server, potentially leading to remote code execution, data manipulation, or unauthorized access to sensitive information.
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H