CVE-2021-46362

CRITICAL

Magnolia <6.2.3 - RCE

Title source: llm

Description

A Server-Side Template Injection (SSTI) vulnerability in the Registration and Forgotten Password forms of Magnolia v6.2.3 and below allows attackers to execute arbitrary code via a crafted payload entered into the fullname parameter.

Exploits (1)

nomisec WRITEUP
by mbadanoiu · poc
https://github.com/mbadanoiu/CVE-2021-46362

Scores

CVSS v3 9.8
EPSS 0.0178
EPSS Percentile 82.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-94
Status published
Products (1)
magnolia-cms/magnolia_cms < 6.2.4
Published Feb 11, 2022
Tracked Since Feb 18, 2026