CVE-2021-23803
CRITICALlatte < 2.10.6 - Incorrect Authorization via Control Character Bypass
Title source: llmDescription
This affects the package latte/latte before 2.10.6. There is a way to bypass allowFunctions that will affect the security of the application. When the template is set to allow/disallow the use of certain functions, adding control characters (x00-x08) after the function will bypass these restrictions.
References (3)
Core 3
Core References
Exploit, Patch, Third Party Advisory x_refsource_misc
https://snyk.io/vuln/SNYK-PHP-LATTELATTE-1932226
Exploit, Issue Tracking, Patch, Third Party Advisory x_refsource_misc
https://github.com/nette/latte/issues/279
Patch, Third Party Advisory x_refsource_misc
https://github.com/nette/latte/commit/227c86eda9a8a6d060ea8501923e768b6d992210
Scores
CVSS v3
9.8
EPSS
0.0158
EPSS Percentile
72.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-863
Status
published
Products (2)
latte/latte
0 - 2.10.6Packagist
nette/latte
< 2.10.6
Published
Dec 17, 2021
Tracked Since
Feb 18, 2026