← Back

CVE-2022-25967

nvd nist
Published: Jan 30, 2023Modified: Mar 27, 2025

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

Versions of the package eta before 2.0.0 are vulnerable to Remote Code Execution (RCE) by overwriting template engine configuration variables with view options received from The Express render API. **Note:** This is exploitable only for users who are rendering templates with user-defined data.

Affected (1)

Products: Eta.js: Eta
1 product
Eta
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 2.0.0

Timeline

No history available yet.