Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Matthid

#24831of 53,622
9.8Total CVSS
Vulnerabilities · 1
PT-2022-12906
9.8
2022-03-06
Antaris · Razorengine · CVE-2021-46703
**Name of the Vulnerable Software and Affected Versions** Antaris RazorEngine versions through 4.5.1-alpha001 **Description** An attacker can execute arbitrary .NET code in a sandboxed environment if users can externally control template contents. This issue affects products that are no longer supported by the maintainer. **Recommendations** For versions through 4.5.1-alpha001, consider restricting access to the IsolatedRazorEngine component to prevent external control of template contents until a supported version is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.