PT-2020-19793 · I18N · I18N
Chris Stephens
·
Published
2020-12-11
·
Updated
2022-09-02
·
CVE-2020-7791
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
i18n versions prior to 2.1.15
Description
The issue arises from insufficient handling of erroneous language tags in the files src/i18n/Concrete/TextLocalizer.cs and src/i18n/LocalizedApplication.cs. This results in a vulnerability that affects the package i18n.
Recommendations
For versions prior to 2.1.15, update to version 2.1.15 or later to resolve the issue. As a temporary workaround, consider restricting access to the
TextLocalizer.cs and LocalizedApplication.cs files until a patch is applied. Avoid using erroneous language tags in the affected files to minimize the risk of exploitation.Fix
RCE
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
I18N