CVE-2021-46362: Code Injection
Published Feb 11, 2022
·Updated
A Server-Side Template Injection (SSTI) vulnerability in the Registration and Forgotten Password forms of Magnolia v6.2.3 and below allows attackers to execute arbitrary code via a crafted payload entered into the fullname parameter.
Affected Software
1 affected component
Magnolia-cms Magnolia Cms<6.2.4
Event History
Feb 11, 2022
CVE Published
via MITRE·08:08 PM
Data Sourced
via MITRE·08:08 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-46362?
CVE-2021-46362 has a critical severity rating due to the potential for remote code execution.
2
How do I fix CVE-2021-46362?
To fix CVE-2021-46362, upgrade Magnolia CMS to version 6.2.4 or later.
3
Who is affected by CVE-2021-46362?
CVE-2021-46362 affects users running Magnolia CMS version 6.2.3 and below.
4
What are the potential impacts of CVE-2021-46362?
CVE-2021-46362 allows attackers to execute arbitrary code on the server, leading to data compromise.
5
What is the nature of CVE-2021-46362?
CVE-2021-46362 is a Server-Side Template Injection (SSTI) vulnerability in the Registration and Forgotten Password forms.