PT-2024-31468 · Unknown · Filesender
Jonathan Bouman
·
Published
2024-09-10
·
Updated
2024-10-07
·
CVE-2024-45186
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FileSender versions prior to 2.49
Description
The issue allows unauthorized users to exploit the server’s template processing function, gaining access to critical credentials stored on the server. This is due to a server-side template injection (SSTI) flaw. Over 600 instances are potentially affected.
Recommendations
For versions prior to 2.49, update to version 2.49 or later to resolve the issue. As a temporary workaround, consider restricting access to the template processing function until a patch is applied. Avoid using vulnerable template injection endpoints until the issue is resolved.
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Filesender