Exploitation Summary
EIP tracks 1 public exploit for CVE-2024-33883. PoCs published by Grantzile.
AI-analyzed exploit summary This repository contains a functional PoC for CVE-2024-33883, demonstrating a prototype pollution attack in EJS (Embedded JavaScript templates) leading to RCE. The exploit leverages insufficient validation in EJS to manipulate the `escapeFunction` option via prototype pollution, allowing arbitrary code execution.
Description
The ejs (aka Embedded JavaScript templates) package before 3.1.10 for Node.js lacks certain pollution protection.
Exploits (1)
This repository contains a functional PoC for CVE-2024-33883, demonstrating a prototype pollution attack in EJS (Embedded JavaScript templates) leading to RCE. The exploit leverages insufficient validation in EJS to manipulate the `escapeFunction` option via prototype pollution, allowing arbitrary code execution.
References (3)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L