PT-2026-45879 · Alf.Io · Alf.Io
CVSS v3.1
8.0
High
| Vector | AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
alf.io versions prior to 2.0-M5-2606
Description
A sandbox escape issue exists in the extension script engine of alf.io, an open source ticket reservation system. An authenticated administrator can execute arbitrary operating system commands on the server. The system uses a sandboxed Rhino environment to execute restricted JavaScript; however, an incomplete AST (Abstract Syntax Tree) blocklist and an unguarded injected Java object
returnClass allow the sandbox to be bypassed using Java reflection. This flaw can be triggered through the Extensions API.Recommendations
Update to version 2.0-M5-2606.
Exploit
Fix
RCE
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alf.Io