PT-2022-12669 · Magnolia · Magnolia Cms

Published

2022-02-11

·

Updated

2022-02-22

·

CVE-2021-46361

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Magnolia CMS versions 6.2.11 and below
Description An issue in the Freemark Filter of Magnolia CMS allows attackers to bypass security restrictions and execute arbitrary code via a crafted FreeMarker payload.
Recommendations For Magnolia CMS versions 6.2.11 and below, update to a version above 6.2.11 to resolve the issue. As a temporary workaround, consider restricting access to the Freemark Filter to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-46361
GHSA-M4HG-5P2M-FM5M

Affected Products

Magnolia Cms