CVE-2021-23369
MEDIUMhandlebars < 4.7.7 - Remote Code Execution via Untrusted Template Compilation
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2021-23369. PoCs published by fazilbaig1, dinhvaren.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2021-23369, a Remote Code Execution (RCE) vulnerability in Handlebars versions before 4.7.7. The exploit leverages a malicious template payload to achieve arbitrary code execution, while the scanner checks for Handlebars usage in the target.
Description
The package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates coming from an untrusted source.
Exploits (2)
This repository contains a functional exploit for CVE-2021-23369, a Remote Code Execution (RCE) vulnerability in Handlebars versions before 4.7.7. The exploit leverages a malicious template payload to achieve arbitrary code execution, while the scanner checks for Handlebars usage in the target.
This repository contains a functional PoC for CVE-2021-23369, a template injection vulnerability in Handlebars. The server.js file demonstrates a vulnerable Handlebars compilation endpoint that allows arbitrary code execution via crafted templates.
References (7)
Scores
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L