{"id":"GHSA-9fcp-vcq9-9h2h","summary":"OS Command Injection in craftercms:crafter-studio","details":"A Server-Side Template Injection issue was discovered in Crafter CMS 3.0.18. Attackers with developer privileges may execute OS commands by Creating/Editing a template file (.ftl filetype) that triggers a call to freemarker.template.utility.Execute in the FreeMarker library during rendering of a web page.","aliases":["CVE-2018-19907"],"modified":"2023-11-01T04:49:17.905524Z","published":"2018-12-19T19:24:18Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-78"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2020-06-16T21:28:17Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-19907"},{"type":"WEB","url":"https://github.com/craftercms/craftercms/issues/2677"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-9fcp-vcq9-9h2h"},{"type":"PACKAGE","url":"https://github.com/craftercms/craftercms"},{"type":"WEB","url":"https://medium.com/@buxuqua/rce-vulnerability-in-crafter-cms-server-side-template-injection-19d8708ce242"}],"affected":[{"package":{"name":"org.craftercms:crafter-studio","ecosystem":"Maven","purl":"pkg:maven/org.craftercms/crafter-studio"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"3.0.18"}]}],"versions":["3.0.0","3.0.1","3.0.10","3.0.11","3.0.12","3.0.13","3.0.14","3.0.15","3.0.16","3.0.17","3.0.18","3.0.2","3.0.3","3.0.4","3.0.5","3.0.6","3.0.7","3.0.8","3.0.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/12/GHSA-9fcp-vcq9-9h2h/GHSA-9fcp-vcq9-9h2h.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}