CVE-2021-42651

HIGH

Pentest-Collaboration-Framework 1.0.8 - Authenticated Server-Side Template Injection via Reports Endpoint

Title source: llm
STIX 2.1

Description

A Server Side Template Injection (SSTI) vulnerability in Pentest-Collaboration-Framework v1.0.8 allows an authenticated remote attacker to execute arbitrary code through /project/PROJECTNAME/reports/.

References (1)

Core 1

Scores

CVSS v3 8.8
EPSS 0.0225
EPSS Percentile 84.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-94
Status published
Products (1)
pentest_collaboration_framework_project/pentest_collaboration_framework 1.0.8
Published May 11, 2022
Tracked Since Feb 18, 2026