CVE-2021-42651

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
11/05/2022
Last modified:
19/05/2022

Description

A Server Side Template Injection (SSTI) vulnerability in Pentest-Collaboration-Framework v1.0.8 allows an authenticated remote attacker to execute arbitrary code through /project/PROJECTNAME/reports/.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pentest_collaboration_framework_project:pentest_collaboration_framework:1.0.8:*:*:*:*:*:*:*