-
Notifications
You must be signed in to change notification settings - Fork 266
Closed
Labels
All For OneSubmissions to the All for One, One for All bountySubmissions to the All for One, One for All bounty
Description
CVE ID(s)
I've only tested this on a sample project but from this simple code search I suspect there are vulnerable projects out there. I'd helpful to see if I can make more robust the query after the initial findings.
Report
Server Side Template Injection in ASP.NET MVC RazorEngine leads to Remote Code Execution vulnerabilities.
More info: Server Side Template Injection (SSTI) in ASP.NET Razor
PR: #4313
- Are you planning to discuss this vulnerability submission publicly? (Blog Post, social networks, etc).
Yes, this is part of a two post series about ASP.NET MVC vulnerabilities and taint tracking with CodeQL.
Result(s)
- You can test this query against the following sample project: RazorVulnerableApp
Metadata
Metadata
Assignees
Labels
All For OneSubmissions to the All for One, One for All bountySubmissions to the All for One, One for All bounty