CVE-2021-46703

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
06/03/2022
Last modified:
04/08/2024

Description

In the IsolatedRazorEngine component of Antaris RazorEngine through 4.5.1-alpha001, an attacker can execute arbitrary .NET code in a sandboxed environment (if users can externally control template contents). NOTE: This vulnerability only affects products that are no longer supported by the maintainer

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:razorengine_project:razorengine:*:*:*:*:*:*:*:* 4.5.1 (excluding)
cpe:2.3:a:razorengine_project:razorengine:4.5.1:alpha001:*:*:*:*:*:*


References to Advisories, Solutions, and Tools