Sploitus

CVE-2018-19907

No indexed exploits for CVE-2018-19907 yet

A Server-Side Template Injection issue was discovered in Crafter CMS 3.0.18. Attackers with developer privileges may execute OS commands by Creating/Editing a template file (.ftl filetype) that triggers a call to freemarker.template.utility.Execute in the FreeMarker library during rendering of a web page.

Affected products
Crafter Cms, Freemarker
Craftercms Crafter Cms
≤ 3.0.18
Fix
Available
CVSS 3.0
8.8 HIGH
EPSS
1.7% (75th percentile)
Weakness
CWE-78
NVD status
Modified
Published
2018-12-06
CVE-2018-19907 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2018-19907 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2018-19907 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.