VendorsXiandafubeetl3.15.12
Vulnerabilities

Xiandafu Beetl 3.15.12

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1CVEs
CVE-2024-22533
Before Beetl v3.15.12, the rendering template has a server-side template injection (SSTI) vulnerability. When the incoming template is controllable, it will be filtered by the DefaultNativeSecurityManager blacklist. Because blacklist filtering is not strict, the blacklist can be bypassed, leading to arbitrary code execution.
Published 2024-02-02 · Modified
9.8EPSS 0.010