CVE-2024-32404

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
26/04/2024
Last modified:
30/06/2025

Description

Server-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1, allows remote attackers to execute arbitrary code via a crafted payload to the Markup Sandbox feature.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:inducer:relate:*:*:*:*:*:*:*:* 2024.1 (excluding)