Sploitus

CVE-2022-24881

No indexed exploits for CVE-2022-24881 yet

Ballcat Codegen provides the function of online editing code to generate templates. In versions prior to 1.0.0.beta.2, attackers can implement remote code execution through malicious code injection of the template engine. This happens because Velocity and freemarker templates are introduced but input verification is not done. The fault is rectified in version 1.0.0.beta.2.

Ballcat Codegen
< 1.0.0
Fix
Available
CVSS 3.1
9.8 CRITICAL
EPSS
3.0% (86th percentile)
Weakness
CWE-94, CWE-20
NVD status
Modified
Published
2022-04-26
CVE-2022-24881 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2022-24881 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2022-24881 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.