CVE-2023-26546

European Chemicals Agency IUCLID before 6.27.6 allows remote authenticated users to execute arbitrary code via Server Side Template Injection (SSTI) with a crafted template file. The attacker must have template manager permission.
Configurations

Configuration 1 (hide)

cpe:2.3:a:echa.europa:iuclid:*:*:*:*:*:*:*:*

History

30 Jan 2025, 17:15

Type Values Removed Values Added
CWE CWE-94

Information

Published : 2023-05-02 20:15

Updated : 2025-01-30 17:15


NVD link : CVE-2023-26546

Mitre link : CVE-2023-26546

CVE.ORG link : CVE-2023-26546


JSON object : View

Products Affected

echa.europa

  • iuclid
CWE
NVD-CWE-Other CWE-94

Improper Control of Generation of Code ('Code Injection')