PT-2022-13104 · Mustache+1 · Mustache+1

Bobthecow

·

Published

2022-01-21

·

Updated

2023-08-25

·

CVE-2022-0323

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions mustache/mustache versions 2.0.0 through 2.14.0
Description The issue is related to the improper neutralization of special elements used in a template engine. This can lead to arbitrary PHP code execution, even when strict callables is set to true, if the section value is controllable.
Recommendations For versions 2.0.0 through 2.14.0, update to version 2.14.1 or later to resolve the issue.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

ALT-PU-2023-2012
ALT-PU-2023-2057
ALT-PU-2023-5127
CVE-2022-0323
GHSA-4RMR-C2JX-VX27

Affected Products

Alt Linux
Mustache